SLES

SLES 15 — procps — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — procps — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 April 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2018-1122 CVE-2018-1123 CVE-2018-1124 CVE-2018-1125 CVE-2018-1126 CVE-2023-4016 Upstream summary: procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs […]

Read more
SLES 15 — libSDL2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libSDL2 — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 March 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2017-2888 CVE-2022-4743 CVE-2019-13626 Upstream summary: An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can […]

Read more
SLES 15 — libldap — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libldap — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 28 March 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1018-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-29155 CVE-2015-6908 CVE-2020-12243 CVE-2020-25692 CVE-2020-36221 CVE-2020-36222 CVE-2020-36223 CVE-2020-36224  +12 more Upstream summary: In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability […]

Read more
SLES 12 — shadow — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — shadow — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 March 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-6252 CVE-2013-4235 CVE-2023-29383 CVE-2017-12424 CVE-2018-7169 CVE-2023-4641 Upstream summary: Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap. Table […]

Read more
SLES 15 — kernel-azure — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — kernel-azure — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 March 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3897-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-3623 CVE-2021-4159 Upstream summary: A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function follow_page_pte […]

Read more
SLES 15 — python2-dnspython — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-dnspython — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 March 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:9423 (see also SUSE bugzilla) Related CVEs: CVE-2023-29483 Upstream summary: eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an […]

Read more
SLES 15 — libksba8 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libksba8 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 19 March 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:2627-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-3515 CVE-2022-47629 CVE-2014-9087 CVE-2016-4574 CVE-2016-4579 Upstream summary: A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The […]

Read more
SLES 12 — libmfx — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libmfx — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 March 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3198-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-22656 CVE-2023-45221 CVE-2023-47169 CVE-2023-47282 CVE-2023-48368 Upstream summary: Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated […]

Read more
SLES 12 — docker-distribution-registry — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — docker-distribution-registry — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 March 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory GHSA-hqxw-f8mx-cpmw (see also SUSE bugzilla) Related CVEs: CVE-2023-2253 CVE-2017-11468 Upstream summary: A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records […]

Read more
CHAT