SLES

SLES 15 — tgt — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — tgt — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02591-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-45751 Upstream summary: tgt (aka Linux target framework) before 1.0.93 attempts to achieve entropy by calling rand without srand. The PRNG seed is always 1, […]

Read more
SLES 15 — dmidecode — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — dmidecode — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:1494-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-30630 Upstream summary: Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo […]

Read more
SLES 12 — libgcrypt20 — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libgcrypt20 — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 January 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:254-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-33560 CVE-2024-2236 CVE-2013-4242 CVE-2014-3591 CVE-2015-0837 CVE-2015-7511 CVE-2016-6313 CVE-2017-9526  +2 more Upstream summary: Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks […]

Read more
SLES 15 — python2-WebOb — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-WebOb — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2969-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-42353 Upstream summary: WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does […]

Read more
SLES 15 — subversion — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — subversion — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:1161-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24070 CVE-2017-9800 CVE-2019-0203 CVE-2020-17525 CVE-2024-46901 CVE-2021-28544 CVE-2009-2411 CVE-2010-3315  +12 more Upstream summary: Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, […]

Read more
SLES 15 — zypper — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — zypper — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-7685 CVE-2017-7436 CVE-2017-9269 CVE-2017-9271 CVE-2018-20532 CVE-2018-20533 CVE-2019-18900 CVE-2024-0217  +1 more Upstream summary: The decoupled download and installation steps in libzypp before 17.5.0 could lead to […]

Read more
SLES 12 — python-cffi — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-cffi — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 January 2024 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:1458-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-23931 Upstream summary: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects […]

Read more
SLES 15 — libzypp-plugin-appdata — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libzypp-plugin-appdata — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 January 2024 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0095-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-22643 Upstream summary: An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-plugin-appdata of SUSE Linux Enterprise Server […]

Read more
SLES 15 — libavif13 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libavif13 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 December 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0423-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-6704 Upstream summary: Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a […]

Read more
SLES 15 — dbus — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — dbus — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 December 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:263-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-35512 CVE-2012-3524 CVE-2023-34969 CVE-2022-42011 CVE-2022-42012 CVE-2020-12049 CVE-2010-1172 CVE-2013-0292  +12 more Upstream summary: A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable […]

Read more
CHAT