openSUSE Security Update: xen
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2012:0886-1
Rating:             critical
References:         #757537 #757970 #764077 
Cross-References:   CVE-2012-0217 CVE-2012-0218 CVE-2012-2934
                   
Affected Products:
                    openSUSE 12.1
______________________________________________________________________________

   An update that fixes three vulnerabilities is now available.

Description:


   This update of XEN fixed multiple security flaws that could
   be exploited by local attackers to cause a Denial of
   Service or potentially escalate privileges. Additionally,
   several other upstream changes were backported.


Patch Instructions:

   To install this openSUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - openSUSE 12.1:

      zypper in -t patch openSUSE-2012-403

   To bring your system up-to-date, use "zypper patch".


Package List:

   - openSUSE 12.1 (i586 x86_64):

      xen-debugsource-4.1.2_17-1.10.1
      xen-devel-4.1.2_17-1.10.1
      xen-kmp-default-4.1.2_17_k3.1.10_1.16-1.10.1
      xen-kmp-default-debuginfo-4.1.2_17_k3.1.10_1.16-1.10.1
      xen-kmp-desktop-4.1.2_17_k3.1.10_1.16-1.10.1
      xen-kmp-desktop-debuginfo-4.1.2_17_k3.1.10_1.16-1.10.1
      xen-libs-4.1.2_17-1.10.1
      xen-libs-debuginfo-4.1.2_17-1.10.1
      xen-tools-domU-4.1.2_17-1.10.1
      xen-tools-domU-debuginfo-4.1.2_17-1.10.1

   - openSUSE 12.1 (x86_64):

      xen-4.1.2_17-1.10.1
      xen-doc-html-4.1.2_17-1.10.1
      xen-doc-pdf-4.1.2_17-1.10.1
      xen-libs-32bit-4.1.2_17-1.10.1
      xen-libs-debuginfo-32bit-4.1.2_17-1.10.1
      xen-tools-4.1.2_17-1.10.1
      xen-tools-debuginfo-4.1.2_17-1.10.1

   - openSUSE 12.1 (ia64):

      xen-libs-debuginfo-x86-4.1.2_17-1.10.1
      xen-libs-x86-4.1.2_17-1.10.1

   - openSUSE 12.1 (i586):

      xen-kmp-pae-4.1.2_17_k3.1.10_1.16-1.10.1
      xen-kmp-pae-debuginfo-4.1.2_17_k3.1.10_1.16-1.10.1


References:

   https://www.suse.com/security/cve/CVE-2012-0217.html
   https://www.suse.com/security/cve/CVE-2012-0218.html
   https://www.suse.com/security/cve/CVE-2012-2934.html
   https://bugzilla.novell.com/757537
   https://bugzilla.novell.com/757970
   https://bugzilla.novell.com/764077

openSUSE: 2012:0886-1: critical: xen

July 18, 2012
An update that fixes three vulnerabilities is now available

Description

This update of XEN fixed multiple security flaws that could be exploited by local attackers to cause a Denial of Service or potentially escalate privileges. Additionally, several other upstream changes were backported.

 

Patch

Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 12.1: zypper in -t patch openSUSE-2012-403 To bring your system up-to-date, use "zypper patch".


Package List

- openSUSE 12.1 (i586 x86_64): xen-debugsource-4.1.2_17-1.10.1 xen-devel-4.1.2_17-1.10.1 xen-kmp-default-4.1.2_17_k3.1.10_1.16-1.10.1 xen-kmp-default-debuginfo-4.1.2_17_k3.1.10_1.16-1.10.1 xen-kmp-desktop-4.1.2_17_k3.1.10_1.16-1.10.1 xen-kmp-desktop-debuginfo-4.1.2_17_k3.1.10_1.16-1.10.1 xen-libs-4.1.2_17-1.10.1 xen-libs-debuginfo-4.1.2_17-1.10.1 xen-tools-domU-4.1.2_17-1.10.1 xen-tools-domU-debuginfo-4.1.2_17-1.10.1 - openSUSE 12.1 (x86_64): xen-4.1.2_17-1.10.1 xen-doc-html-4.1.2_17-1.10.1 xen-doc-pdf-4.1.2_17-1.10.1 xen-libs-32bit-4.1.2_17-1.10.1 xen-libs-debuginfo-32bit-4.1.2_17-1.10.1 xen-tools-4.1.2_17-1.10.1 xen-tools-debuginfo-4.1.2_17-1.10.1 - openSUSE 12.1 (ia64): xen-libs-debuginfo-x86-4.1.2_17-1.10.1 xen-libs-x86-4.1.2_17-1.10.1 - openSUSE 12.1 (i586): xen-kmp-pae-4.1.2_17_k3.1.10_1.16-1.10.1 xen-kmp-pae-debuginfo-4.1.2_17_k3.1.10_1.16-1.10.1


References

https://www.suse.com/security/cve/CVE-2012-0217.html https://www.suse.com/security/cve/CVE-2012-0218.html https://www.suse.com/security/cve/CVE-2012-2934.html https://bugzilla.novell.com/757537 https://bugzilla.novell.com/757970 https://bugzilla.novell.com/764077


Severity
Announcement ID: openSUSE-SU-2012:0886-1
Rating: critical
Affected Products: openSUSE 12.1 .

Related News