SLES

SLES 16 — python313-httptools — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — python313-httptools — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2022:137-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-22959 CVE-2021-22960 CVE-2022-32213 CVE-2022-32214 CVE-2022-32215 CVE-2023-30589 Upstream summary: The parser in accepts requests with a space (SP) right after the header name before the colon. […]

Read more
SLES 15 — yast2-devtools — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — yast2-devtools — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2018:1890-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-17042 Upstream summary: lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to […]

Read more
SLES 12 — at — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — at — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:723-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8079 CVE-2016-6354 Upstream summary: qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db. Table of contents Symptom & Impact Environment & Reproduction […]

Read more
SLES 12 — pam — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — pam — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory RHSA-2024:10379 (see also SUSE bugzilla) Related CVEs: CVE-2024-10041 CVE-2024-22365 CVE-2010-3430 CVE-2010-3431 CVE-2010-3853 CVE-2011-3148 CVE-2014-2583 CVE-2015-3238  +1 more Upstream summary: A vulnerability was found in PAM. The secret information is stored in memory, […]

Read more
SLES 12 — guile — vulnerability — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — guile — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2017:0394-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-8605 Upstream summary: The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other […]

Read more
SLES 16 — cracklib — vulnerability — patch and remediation guide — diagnosis and fix on SLES 16

SLES 16 — cracklib — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 16 📖 ~4 min read  •  Source: SUSE advisory SUSE-CU-2019:695-1 (see also SUSE bugzilla) Related CVEs: CVE-2016-6318 Upstream summary: Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) […]

Read more
SLES 12 — gegl — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — gegl — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2021:4193-1 (see also SUSE bugzilla) Related CVEs: CVE-2021-45463 CVE-2018-10113 CVE-2012-4433 Upstream summary: load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or […]

Read more
SLES 15 — python311-loguru — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — python311-loguru — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2025:15097-1 (see also SUSE bugzilla) Related CVEs: CVE-2022-0329 Upstream summary: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in […]

Read more
SLES 15 — enigmail — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — enigmail — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2018:1329-1 (see also SUSE bugzilla) Related CVEs: CVE-2017-17688 CVE-2017-17689 CVE-2018-12019 CVE-2014-5369 CVE-2019-12269 Upstream summary: The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, […]

Read more
SLES 12 — libpodofo0_9_2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on SLES 12

SLES 12 — libpodofo0_9_2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: SLES 12 📖 ~4 min read  •  Source: SUSE advisory SUSE-SU-2024:3541-1 (see also SUSE bugzilla) Related CVEs: CVE-2015-8981 CVE-2017-6841 CVE-2017-6842 CVE-2017-6849 CVE-2017-8378 CVE-2019-10723 CVE-2018-12983 CVE-2019-20093  +12 more Upstream summary: Heap-based buffer overflow in the PdfParser::ReadXRefSubsection function in base/PdfParser.cpp in PoDoFo allows attackers […]

Read more
CHAT