SLES

SLES 15 — mdadm — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — mdadm — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3691-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-28736 CVE-2023-28938 Upstream summary: Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of […]

Read more
SLES 15 — libjbig2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libjbig2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-6369 CVE-2022-1210 Upstream summary: Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of […]

Read more
SLES 15 — ceph — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ceph — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:796-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-3650 CVE-2022-0670 CVE-2022-3854 CVE-2021-3979 Upstream summary: A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in […]

Read more
SLES 15 — libQt5Svg5 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libQt5Svg5 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2967-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-45930 CVE-2023-32573 CVE-2021-3481 CVE-2018-19869 Upstream summary: Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from […]

Read more
SLES 15 — saphanabootstrap-formula — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — saphanabootstrap-formula — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0009-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-45153 Upstream summary: An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP […]

Read more
SLES 15 — libaom3 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libaom3 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:0517-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-6879 Upstream summary: Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). Table of contents […]

Read more
SLES 15 — jtidy — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — jtidy — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3016-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-34623 Upstream summary: An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object […]

Read more
SLES 15 — bluez — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — bluez — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9413 (see also SUSE bugzilla) Related CVEs: CVE-2023-50229 CVE-2023-50230 CVE-2023-27349 CVE-2022-39176 CVE-2022-0204 CVE-2019-8921 CVE-2019-8922 CVE-2023-45866  +12 more Upstream summary: BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This […]

Read more
SLES 15 — python2-Mako — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-Mako — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:496-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-40023 Upstream summary: Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects […]

Read more
SLES 12 — kpartx — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — kpartx — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 May 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3707-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-41973 CVE-2022-41974 Upstream summary: multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction with CVE-2022-41974. Local users […]

Read more
CHAT