SLES

SLES 12 — traceroute — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — traceroute — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 June 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3924-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-46316 Upstream summary: In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines. Table of contents Symptom & […]

Read more
SLES 15 — jsch — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — jsch — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:4230-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-48795 Upstream summary: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity […]

Read more
SLES 15 — xterm — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — xterm — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2025:7427 (see also SUSE bugzilla) Related CVEs: CVE-2022-45063 CVE-2021-27135 CVE-2023-40359 CVE-2022-24130 Upstream summary: xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and […]

Read more
SLES 15 — ivy-local — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ivy-local — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:712-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-37865 CVE-2022-37866 Upstream summary: With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if […]

Read more
SLES 15 — libapr1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libapr1 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3428-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-49582 CVE-2011-0419 CVE-2011-1928 Upstream summary: Lax permissions set by the Apache Portable Runtime library on Unix platforms would allow local users read access to named […]

Read more
SLES 15 — eclipse-jdt — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — eclipse-jdt — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 June 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2021:0485-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-27225 CVE-2023-4218 Upstream summary: In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local […]

Read more
SLES 15 — aws-iam-authenticator — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — aws-iam-authenticator — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:2583-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-2385 Upstream summary: A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges. […]

Read more
SLES 12 — audiofile — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — audiofile — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 May 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0940-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-7747 CVE-2018-17095 CVE-2019-13147 CVE-2022-24599 CVE-2017-6827 CVE-2017-6828 CVE-2017-6829 CVE-2017-6830  +10 more Upstream summary: Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File […]

Read more
SLES 12 — libapr-util1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libapr-util1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 27 May 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:348-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-25147 CVE-2017-12618 Upstream summary: Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds […]

Read more
SLES 12 — ucode-amd — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — ucode-amd — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:3330-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-12321 CVE-2023-31315 CVE-2021-26345 CVE-2021-46766 CVE-2021-46774 CVE-2022-23820 CVE-2022-23830 CVE-2023-20519  +12 more Upstream summary: Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may […]

Read more
CHAT