SLES

SLES 15 — graphviz — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — graphviz — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 9 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:1646-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-18032 CVE-2023-46045 CVE-2018-10196 CVE-2019-11023 Upstream summary: Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary […]

Read more
SLES 15 — python2-wheel — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-wheel — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:158-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-40898 Upstream summary: An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via […]

Read more
SLES 15 — kubernetes1.18-client — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — kubernetes1.18-client — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 May 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2021:322-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-3121 CVE-2023-2727 CVE-2023-2728 Upstream summary: An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue. […]

Read more
SLES 12 — libwebp5 — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libwebp5 — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 1 May 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:1830-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-25009 CVE-2018-25010 CVE-2018-25011 CVE-2018-25012 CVE-2018-25013 CVE-2020-36331 CVE-2023-4863 CVE-2023-1999  +3 more Upstream summary: A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in […]

Read more
SLES 12 — python-wheel — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — python-wheel — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 April 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:158-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-40898 Upstream summary: An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via […]

Read more
SLES 12 — wpa_supplicant — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — wpa_supplicant — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 April 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:0716-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-23304 CVE-2019-9494 CVE-2019-9498 CVE-2021-0326 CVE-2021-27803 CVE-2022-23303 CVE-2019-9499 CVE-2023-52160  +12 more Upstream summary: The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are […]

Read more
SLES 15 — python2-Flask — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-Flask — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:1835-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-30861 CVE-2018-1000656 Upstream summary: Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended […]

Read more
SLES 15 — python311-Flask-Security-Too — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-Flask-Security-Too — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2023-49438 Upstream summary: An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted […]

Read more
SLES 12 — shim — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — shim — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 April 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory ESSA-2025:0001 (see also SUSE bugzilla) Related CVEs: CVE-2023-40547 CVE-2022-28737 CVE-2020-10713 CVE-2023-40546 CVE-2023-40549 CVE-2023-40550 CVE-2023-40551 CVE-2023-40548  +4 more Upstream summary: A remote code execution vulnerability was found in Shim. The Shim boot support […]

Read more
SLES 15 — libprotobuf-c1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libprotobuf-c1 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3915-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-48468 CVE-2022-33070 Upstream summary: protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
CHAT