SLES

SLES 12 — libvpx1 — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libvpx1 — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 February 2023 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3940-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-5217 CVE-2019-9232 CVE-2019-9433 CVE-2020-0034 CVE-2017-13194 Upstream summary: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed […]

Read more
SLES 15 — libpixman — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libpixman — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 January 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:4148-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-44638 Upstream summary: In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow […]

Read more
SLES 15 — libcapnp — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libcapnp — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 January 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:4478-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-46149 Upstream summary: Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and […]

Read more
SLES 15 — e2fsprogs — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — e2fsprogs — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 January 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1021-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-1304 CVE-2015-0247 CVE-2015-1572 CVE-2019-5094 CVE-2019-5188 Upstream summary: An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly […]

Read more
SLES 15 — fwupd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — fwupd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 January 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2020:1681-1 (see also SUSE bugzilla) Related CVEs: CVE-2020-10759 CVE-2022-3287 Upstream summary: A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As […]

Read more
SLES 15 — python311-oss2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-oss2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 January 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-RU-2024:1829-1 (see also SUSE bugzilla) Related CVEs: CVE-2023-52323 Upstream summary: PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. Table of contents Symptom & Impact […]

Read more
SLES 15 — amazon-ssm-agent — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — amazon-ssm-agent — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 January 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:1510-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-29527 Upstream summary: Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to […]

Read more
SLES 15 — qatengine — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — qatengine — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 January 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:3290-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-43507 Upstream summary: Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation […]

Read more
SLES 15 — libbpf0 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — libbpf0 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 January 2023 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:0405-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-3534 Upstream summary: A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the […]

Read more
SLES 12 — libpcre2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libpcre2 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 December 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1680-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-1587 CVE-2022-41409 Upstream summary: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects […]

Read more
CHAT