SLES

SLES 15 — python3-oslo.utils — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python3-oslo.utils — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 December 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2025:02448-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-0718 Upstream summary: A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect […]

Read more
SLES 12 — libyajl2 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libyajl2 — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 December 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:2276-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24795 Upstream summary: yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` […]

Read more
SLES 12 — unzip — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — unzip — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 December 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2015:0026-1 (see also SUSE bugzilla) Related CVEs: CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2014-9636 CVE-2018-1000035 CVE-2022-0529 CVE-2022-0530 CVE-2014-9913  +4 more Upstream summary: Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier […]

Read more
SLES 12 — rsyslog — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — rsyslog — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 December 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-IU-2022:632-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24903 CVE-2014-3634 CVE-2018-16881 CVE-2019-17041 CVE-2019-17042 CVE-2011-3200 CVE-2013-4758 CVE-2013-6370  +3 more Upstream summary: Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception […]

Read more
SLES 12 — libldap — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libldap — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 2 December 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:1018-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-29155 CVE-2020-12243 CVE-2020-25692 CVE-2020-36221 CVE-2020-36222 CVE-2020-36223 CVE-2020-36224 CVE-2020-36225  +12 more Upstream summary: In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability […]

Read more
SLES 12 — subversion — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — subversion — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 November 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:1161-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-24070 CVE-2020-17525 CVE-2017-9800 CVE-2019-0203 CVE-2021-28544 CVE-2009-2411 CVE-2010-3315 CVE-2010-4539  +12 more Upstream summary: Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, […]

Read more
SLES 15 — permissions — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — permissions — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 November 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:2345-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-31252 CVE-2019-3687 CVE-2019-3690 CVE-2020-8013 Upstream summary: A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE […]

Read more
SLES 12 — php72 — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — php72 — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 November 2022 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2022:2161-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-31625 CVE-2022-31626 CVE-2020-36193 CVE-2020-7069 CVE-2021-21702 CVE-2021-21704 CVE-2022-31628 CVE-2022-31629  +7 more Upstream summary: In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, […]

Read more
SLES 15 — hwloc-data — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — hwloc-data — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 November 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory Related CVEs: CVE-2022-47022 Upstream summary: An issue was discovered in open-mpi hwloc 2.1.0 allows attackers to cause a denial of service or other unspecified impacts via glibc-cpuset in topology-linux.c. Table of […]

Read more
SLES 15 — python2-ujson — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python2-ujson — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 November 2022 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2023:2134-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-45958 CVE-2022-31116 CVE-2022-31117 Upstream summary: UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use […]

Read more
CHAT