SLES

SLES 12 — libjbig2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libjbig2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 March 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2013-6369 CVE-2022-1210 Upstream summary: Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of […]

Read more
SLES 15 — dhcp — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — dhcp — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 March 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2021:537-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-25217 CVE-2018-5732 CVE-2019-6470 CVE-2022-2928 CVE-2022-2929 CVE-2009-1892 CVE-2010-2156 CVE-2010-3611  +12 more Upstream summary: In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches […]

Read more
SLES 15 — libcue2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcue2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 March 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:4090-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-43641 Upstream summary: libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. […]

Read more
SLES 12 — xerces-j2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — xerces-j2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 March 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:712-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-23437 Upstream summary: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ […]

Read more
SLES 12 — libxerces-c — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libxerces-c — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 March 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:8795 (see also SUSE bugzilla) Related CVEs: CVE-2023-37536 CVE-2017-12627 CVE-2018-1311 CVE-2009-1885 CVE-2015-0252 CVE-2016-0729 CVE-2016-2099 CVE-2016-4463 Upstream summary: An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound […]

Read more
SLES 12 — dmidecode — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — dmidecode — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 February 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2023:1494-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-30630 Upstream summary: Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo […]

Read more
SLES 15 — ruby2.5-rubygem-nokogiri — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — ruby2.5-rubygem-nokogiri — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 February 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:3890-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24836 CVE-2022-29181 CVE-2018-3740 CVE-2019-5477 CVE-2015-8241 CVE-2015-8317 CVE-2016-5131 CVE-2017-15412  +3 more Upstream summary: Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< […]

Read more
SLES 15 — libsasl2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libsasl2 — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 February 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1151-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24407 CVE-2019-19906 CVE-2020-8032 CVE-2009-0688 Upstream summary: In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or […]

Read more
SLES 12 — libcjose0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libcjose0 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 February 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3030-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-37464 Upstream summary: OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag […]

Read more
SLES 15 — libmozjs — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libmozjs — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 19 February 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3837-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-5168 CVE-2023-5169 CVE-2023-5171 CVE-2023-5174 CVE-2023-5176 CVE-2023-5732 CVE-2023-5721 CVE-2023-5724  +12 more Upstream summary: A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in […]

Read more
CHAT