SUSE Alert
2543Warning Date
Severity Level
Warning Number
Target Sector
24 February, 2022
● High
2022-4431
All
SUSE has released security updates to address several vulnerabilities in several products, mainly:
- cyrus-sasl
- SUSE Linux Enterprise Debuginfo 11-SP3
- SUSE Linux Enterprise Debuginfo 11-SP4
- SUSE Linux Enterprise Point of Sale 11-SP3
- SUSE Linux Enterprise Server 11-SECURITY
- SUSE Linux Enterprise Server 11-SP4-LTSS
- MozillaThunderbird
- SUSE Linux Enterprise Desktop 15-SP3
- SUSE Linux Enterprise Server 15-SP3
- SUSE Linux Enterprise Server for SAP Applications 15-SP3
- SUSE Linux Enterprise Workstation Extension 15-SP3
Attacker could exploit these vulnerabilities by doing the following:
- Escalation of privilege
- Unauthorized disclosure of information
- Bypass of a protection mechanism
- SQL injection
The CERT team encourages users to review SUSE security advisory and apply the necessary updates: