SLES

SLES 12 — saphanabootstrap-formula — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — saphanabootstrap-formula — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 April 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0009-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-45153 Upstream summary: An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP […]

Read more
SLES 15 — libctf0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libctf0 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:3179-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-44840 CVE-2022-47673 CVE-2022-47695 CVE-2022-47696 CVE-2020-19726 CVE-2022-45703 CVE-2021-20294 CVE-2022-35205  +12 more Upstream summary: Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in […]

Read more
SLES 15 — sysstat — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — sysstat — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:0026-1 (see also SUSE bugzilla) Related CVEs: CVE-2019-19725 CVE-2023-33204 CVE-2022-39377 CVE-2019-16167 CVE-2018-19416 CVE-2018-19517 Upstream summary: sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c. Table of contents Symptom & Impact […]

Read more
SLES 15 — go1.17 — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — go1.17 — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1298-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-30580 CVE-2022-32189 CVE-2022-1705 CVE-2022-1962 CVE-2022-28131 CVE-2022-30630 CVE-2022-30631 CVE-2022-30632  +9 more Upstream summary: Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows […]

Read more
SLES 15 — distribution-registry — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — distribution-registry — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory GHSA-hqxw-f8mx-cpmw (see also SUSE bugzilla) Related CVEs: CVE-2023-2253 CVE-2017-11468 Upstream summary: A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records […]

Read more
SLES 15 — aws-efs-utils — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — aws-efs-utils — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:3954-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-35881 CVE-2022-46174 Upstream summary: An issue was discovered in the traitobject crate through 2020-06-01 for Rust. It has false expectations about fat pointers, possibly causing […]

Read more
SLES 15 — redis7 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — redis7 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2925-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-36824 CVE-2023-28425 CVE-2023-41053 Upstream summary: Redis is an in-memory database that persists on disk. In Redit 7.0 prior to 7.0.12, extracting key names from a […]

Read more
SLES 15 — python3-py — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-py — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:338-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-42969 Upstream summary: The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a […]

Read more
SLES 15 — espeak-ng — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — espeak-ng — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:2632-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-49990 CVE-2023-49991 CVE-2023-49992 CVE-2023-49993 CVE-2023-49994 Upstream summary: Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c. Table of contents Symptom […]

Read more
SLES 12 — libsasl2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libsasl2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 April 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1151-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24407 CVE-2019-19906 CVE-2009-0688 Upstream summary: In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE […]

Read more
CHAT