Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

openSUSE: 2016:0914-1 Important: Xen Buffer Overflow and Other Issues

opensuse
Calendar Grey March 30, 2016
Scroller Opensuse
Crucial security enhancement for openSUSE xen addressing 30 vulnerabilities and implementing 6 high-priority fixes to bolster system integrity and protect against threats.
An update that solves 26 vulnerabilities and has 5 fixes is An update that solves 26 vulnerabilities and has 5 fixes is An update that solves 26 vulnerabilities and has 5 fixes is ...

Description

xen was updated to fix 26 security issues.

These security issues were fixed:

- CVE-2013-4533: Buffer overflow in the pxa2xx_ssp_load function in

hw/arm/pxa2xx.c allowed remote attackers to cause a denial of service or

possibly execute arbitrary code via a crafted s->rx_level value in a

savevm image (bsc#864655).

- CVE-2013-4537: The ssi_sd_transfer function in hw/sd/ssi-sd.c allowed

remote attackers to execute arbitrary code via a crafted arglen value in

a savevm image (bsc#864391).

- CVE-2013-4538: Multiple buffer overflows in the ssd0323_load function in

hw/display/ssd0323.c allowed remote attackers to cause a denial of

service (memory corruption) or possibly execute arbitrary code via

crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and

row_end values; or (5) col_star and col_end values in a savevm image

(bsc#864769).

- CVE-2013-4539: Multiple buffer overflows in the tsc210x_load function in

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-413=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

xen-debugsource-4.5.2_06-12.1

xen-devel-4.5.2_06-12.1

xen-libs-4.5.2_06-12.1

xen-libs-debuginfo-4.5.2_06-12.1

xen-tools-domU-4.5.2_06-12.1

xen-tools-domU-debuginfo-4.5.2_06-12.1

- openSUSE Leap 42.1 (x86_64):

xen-4.5.2_06-12.1

xen-doc-html-4.5.2_06-12.1

xen-kmp-default-4.5.2_06_k4.1.15_8-12.1

xen-kmp-default-debuginfo-4.5.2_06_k4.1.15_8-12.1

xen-libs-32bit-4.5.2_06-12.1

xen-libs-debuginfo-32bit-4.5.2_06-12.1

xen-tools-4.5.2_06-12.1

xen-tools-debuginfo-4.5.2_06-12.1

References

https://www.suse.com/security/cve/CVE-2013-4533.html

https://www.suse.com/security/cve/CVE-2013-4537.html

https://www.suse.com/security/cve/CVE-2013-4538.html

https://www.suse.com/security/cve/CVE-2013-4539.html

https://www.suse.com/security/cve/CVE-2014-0222.html

https://www.suse.com/security/cve/CVE-2014-3689.html

https://www.suse.com/security/cve/CVE-2014-7815.html

https://www.suse.com/security/cve/CVE-2014-9718.html

https://www.suse.com/security/cve/CVE-2015-1779.html

https://www.suse.com/security/cve/CVE-2015-5278.html

https://www.suse.com/security/cve/CVE-2015-6855.html

https://www.suse.com/security/cve/CVE-2015-7512.html

https://www.suse.com/security/cve/CVE-2015-8345.html

https://www.suse.com/security/cve/CVE-2015-8613.html

https://www.suse.com/security/cve/CVE-2015-8619.html

https://www.suse.com/security/cve/CVE-2015-8743.html

https://www.suse.com/security/cve/CVE-2015-8744.html

https://www.suse.com/security/cve/CVE-2015-8745.html

https://www.suse.com/security/cve/CVE-2016-1568.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:0914-1
Rating: important
Affected Products: openSUSE Leap 42.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.