SUSE Updates
2526Warning Date
Severity Level
Warning Number
Target Sector
27 October, 2020
● High
2020-1975
All
Description:
SUSE has released security updates to address multiple vulnerabilities in the following products:
- SDL
- SUSE Linux Enterprise Software Development Kit 12-SP5
- SUSE Linux Enterprise Server 12-SP5
- MozillaFirefox
- SUSE Linux Enterprise Server 11-SP4-LTSS
- SUSE Linux Enterprise Debuginfo 11-SP4
- bluez
- SUSE Linux Enterprise Workstation Extension 15-SP2
- SUSE Linux Enterprise Module for Desktop Applications 15-SP2
- SUSE Linux Enterprise Module for Basesystem 15-SP2
- rmt-server
- SUSE Linux Enterprise Module for Server Applications 15-SP2
- SUSE Linux Enterprise Module for Public Cloud 15-SP2
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Denial of service (DoS)
- Cross-site request forgery (CSRF).
- Cross-site scripting (XSS) attack.
- Execute arbitrary code.
Best practice and Recommendations:
The CERT team encourages users to review SUSE security advisory and apply the necessary updates: