SUSE Updates
2962Warning Date
Severity Level
Warning Number
Target Sector
9 July, 2020
● High
2020-1471
All
Description:
SUSE has released a security updates to address multiple vulnerabilities in the following products:
- LibVNCServer
- SUSE Linux Enterprise Workstation Extension 15-SP2
- SUSE Linux Enterprise Workstation Extension 15-SP1
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1
- nmap
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1
- SUSE Linux Enterprise Module for Basesystem 15-SP2
- texlive-filesystem
- SUSE Linux Enterprise Module for Desktop Applications 15-SP2
- opencv
- SUSE Linux Enterprise Workstation Extension 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1
- MozillaThunderbird
- SUSE Linux Enterprise Workstation Extension 15-SP2
- libEMF
- SUSE Linux Enterprise Workstation Extension 15-SP2
- libexif
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1
- SUSE Linux Enterprise Module for Desktop Applications 15-SP2
- icu
- SUSE Linux Enterprise Module for Server Applications 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1
- freetds
- SUSE Linux Enterprise Module for Server Applications 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1
- osc
- SUSE Linux Enterprise Module for Development Tools 15-SP2
- libvpx
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1
- SUSE Linux Enterprise Module for Desktop Applications 15-SP2
- SUSE Linux Enterprise Module for Basesystem 15-SP2
- python-ecdsa
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2
- SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1
- SUSE Linux Enterprise Module for Basesystem 15-SP2
- MozillaFirefox
- SUSE Linux Enterprise Server 11-SP4-LTSS
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Memory corruption.
- Denial of service (DoS)
- Information disclosure
- Privilege escalation
- Buffer overflow
Best practice and Recommendations:
The CERT team encourages users to review SUSE security advisory and apply the necessary updates:
- https://www.suse.com/support/update/announcement/2020/suse-su-20201873-1/
- https://www.suse.com/support/update/announcement/2019/suse-su-20192425-2/
- https://www.suse.com/support/update/announcement/2020/suse-su-20201580-2/
- https://www.suse.com/support/update/announcement/2019/suse-su-20193192-2/
- https://www.suse.com/support/update/announcement/2020/suse-su-20201591-2/
- https://www.suse.com/support/update/announcement/2020/suse-su-20201621-2/
- https://www.suse.com/support/update/announcement/2020/suse-su-20201553-2/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200819-2/
- https://www.suse.com/support/update/announcement/2020/suse-su-20201417-2/
- https://www.suse.com/support/update/announcement/2020/suse-su-20201695-2/
- https://www.suse.com/support/update/announcement/2020/suse-su-20201297-2/
- https://www.suse.com/support/update/announcement/2019/suse-su-20192891-2/
- https://www.suse.com/support/update/announcement/2020/suse-su-202014421-1/