SLES

SLES 15 — rust1.71 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rust1.71 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:2570-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-38497 Upstream summary: Cargo downloads the Rust project's dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, […]

Read more
SLES 15 — python311-oauthlib — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-oauthlib — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2025:15100-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-36087 Upstream summary: OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious […]

Read more
SLES 12 — ntfs — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ntfs — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 June 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3865-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-40284 CVE-2021-33285 CVE-2021-33286 CVE-2021-33287 CVE-2021-33289 CVE-2021-35266 CVE-2021-35267 CVE-2021-35268  +12 more Upstream summary: A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an […]

Read more
SLES 15 — libapr-util1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libapr-util1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 18 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:348-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-25147 CVE-2017-12618 Upstream summary: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds […]

Read more
SLES 15 — shadow — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — shadow — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2026:1228-1 (see also SUSE bugzilla) Related CVEs: CVE-2013-4235 CVE-2023-29383 CVE-2018-7169 CVE-2023-4641 Upstream summary: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees Table of contents Symptom & Impact Environment […]

Read more
SLES 12 — npm14 — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — npm14 — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 June 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3447-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-44487 CVE-2023-30581 CVE-2022-25881 CVE-2023-23920 CVE-2023-38552 CVE-2023-32006 CVE-2023-32559 CVE-2023-32002  +3 more Upstream summary: The HTTP/2 protocol allows a denial of service (server resource consumption) because request […]

Read more
SLES 15 — rls — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rls — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2019:2439-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-12083 CVE-2020-1967 CVE-2022-21658 CVE-2018-1000622 Upstream summary: The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's […]

Read more
SLES 15 — rmail — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rmail — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3898-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-31256 CVE-2023-51765 Upstream summary: A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail systemd service of openSUSE […]

Read more
SLES 15 — zchunk — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — zchunk — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3619-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-46228 Upstream summary: zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c. Table of contents Symptom & […]

Read more
SLES 12 — tar — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — tar — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 June 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:1498-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-48303 CVE-2021-20193 CVE-2010-0624 CVE-2016-6321 CVE-2023-39804 CVE-2018-20482 CVE-2019-9923 Upstream summary: GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory […]

Read more
CHAT