SUSE Updates
2730Warning Date
Severity Level
Warning Number
Target Sector
25 February, 2020
● Medium
2020-953
All
Description:
SUSE has released security updates to address multiple vulnerabilities in the following products:
- SUSE Linux Enterprise Server 11-SP4-LTSS
- php53
- MozillaFirefox
- SUSE Linux Enterprise Point of Sale 11-SP3
- php53
- SUSE Linux Enterprise Debuginfo 11-SP4
- php53
- SUSE Linux Enterprise Debuginfo 11-SP3
- php53
- SUSE Linux Enterprise Module for Server Applications 15-SP1
- dpdk
- SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
- dpdk
- python-azure-agent
- pdsh, slurm_18_08
- SUSE Linux Enterprise Module for Public Cloud 15-SP1
- python-azure-agent
- SUSE Linux Enterprise Server 11-SECURITY
- openssl1
- SUSE Linux Enterprise Module for HPC 15-SP1
- pdsh, slurm_18_08
- SUSE Linux Enterprise Module for HPC 15
- pdsh, slurm_18_08
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- JavaScript code injection.
- Privilege escalation.
- Buffer overflow.
- Denial of service (DoS).
Best practice and Recommendations:
The CERT team encourages users to review SUSE security advisory and apply the necessary updates:
- https://www.suse.com/support/update/announcement/2020/suse-su-202014289-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-202014290-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200439-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200440-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-202014291-1/
- https://www.suse.com/support/update/announcement/2020/suse-su-20200443-1/