Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2012:1486-1 Important: Xen DoS And Security Fixes Update

suse
Calendar Grey November 16, 2012
Dist Suse Esm H88
SUSE-SU-2013:2023-1 enhances Xen, addressing 10 vulnerabilities with critical updates. Verify your system is secure with the latest patches.
An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes is now...

Summary

XEN was updated to fix various bugs and security issues: The following security issues have been fixed: * CVE-2012-4544: xen: Domain builder Out-of-memory due to malicious kernel/ramdisk (XSA 25) * CVE-2012-4411: XEN / qemu: guest administrator can access qemu monitor console (XSA-19) * CVE-2012-4535: xen: Timer overflow DoS vulnerability (XSA 20) * CVE-2012-4536: xen: pirq range check DoS vulnerability (XSA 21) * CVE-2012-4537: xen: Memory mapping failure DoS vulnerability (XSA 22) * CVE-2012-4538: xen: Unhooking empty PAE entries DoS vulnerability (XSA 23) * CVE-2012-4539: xen: Grant table hypercall infinite loop DoS vulnerability (XSA 24) * CVE-2012-3497: xen: multiple TMEM hypercall vulnerabilities (XSA-15) Also the following bugs have been fixed and upstream patches have been applied: *

References

#777890 #778105 #779212 #784087 #786516 #786517

#786518 #786519 #786520 #787163

Cross- CVE-2012-3497 CVE-2012-4411 CVE-2012-4535

CVE-2012-4536 CVE-2012-4537 CVE-2012-4538

CVE-2012-4539 CVE-2012-4544

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2 for VMware

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2012-3497.html

https://www.suse.com/security/cve/CVE-2012-4411.html

https://www.suse.com/security/cve/CVE-2012-4535.html

https://www.suse.com/security/cve/CVE-2012-4536.html

https://www.suse.com/security/cve/CVE-2012-4537.html

https://www.suse.com/security/cve/CVE-2012-4538.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2012:1486-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here