SLES

SLES 12 — jtidy — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — jtidy — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 July 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3016-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-34623 Upstream summary: An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object […]

Read more
SLES 15 — python3-reportlab — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-reportlab — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 11 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2561-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-33733 CVE-2019-17626 CVE-2019-19450 CVE-2020-28463 Upstream summary: Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file. Table of contents […]

Read more
SLES 15 — supportutils — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — supportutils — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:0480-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-19637 CVE-2018-19639 CVE-2022-45154 CVE-2018-19640 CVE-2018-19638 Upstream summary: Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems […]

Read more
SLES 15 — python2-PyJWT — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-PyJWT — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 10 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1736-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-29217 Upstream summary: PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT […]

Read more
SLES 12 — xz — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xz — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 July 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1007-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-1271 Upstream summary: An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name […]

Read more
SLES 15 — libeconf0 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libeconf0 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3064-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-22652 CVE-2023-30078 CVE-2023-30079 CVE-2023-32181 Upstream summary: A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in openSUSE libeconf leads to DoS via […]

Read more
SLES 15 — telnet — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — telnet — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3471-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-39028 Upstream summary: telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or […]

Read more
SLES 15 — guava — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — guava — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 July 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2503-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-2976 CVE-2020-8908 Upstream summary: Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems […]

Read more
SLES 12 — axis — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — axis — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 June 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0851-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-51441 CVE-2012-5784 CVE-2014-3596 CVE-2018-8032 Upstream summary: ** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin […]

Read more
CHAT