Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE: 2012:0689-1 Important: Kernel SLE11 SP2 Local Exploits

suse
Calendar Grey June 2, 2012
Dist Suse Esm H88
The SUSE kernel upgrade for SLE11 SP2 addresses various local vulnerabilities and enhances overall system security and stability for its users.
An update that solves four vulnerabilities and has 64 fixes An update that solves four vulnerabilities and has 64 fixes An update that solves four vulnerabilities and has 64 fixes ...

Summary

The SUSE Linux Enterprise 11 SP2 kernel was updated to 3.0.31, fixing lots of bugs and security issues. Various security and bug fixes contained in the Linux 3.0 stable releases 3.0.27 up to 3.0.31 are included, but not explicitly listed below. Following security issues were fixed: CVE-2012-2313: The dl2k network card driver lacked permission handling for some ethtool ioctls, which could allow local attackers to start/stop the network card. CVE-2012-2133: A use after free bug in hugetlb support could be used by local attackers to crash the system. CVE-2012-2127: Various leaks in namespace handling over fork where fixed, which could be exploited by e.g. vsftpd access by remote users. CVE-2012-2319: A memory corruption when mounting a hfsplus

References

#704280 #708836 #718521 #721857 #725592 #732296

#738528 #738644 #743232 #744758 #745088 #746938

#748112 #748463 #748806 #748859 #750426 #751550

#752022 #752634 #753172 #753698 #754085 #754428

#754690 #754969 #755178 #755537 #755758 #755812

#756236 #756821 #756840 #756940 #757077 #757202

#757205 #757289 #757373 #757517 #757565 #757719

#757783 #757789 #757950 #758104 #758279 #758532

#758540 #758731 #758813 #758833 #759340 #759539

#759541 #759657 #759908 #759971 #760015 #760279

#760346 #760974 #761158 #761387 #761772 #762285

#762329 #762424

Cross- CVE-2012-2127 CVE-2012-2133 CVE-2012-2313

CVE-2012-2319

Affected Products:

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:0689-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here