Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

SUSE: 2013:0674-1 Important: Kernel Denial of Service Threat

suse
Calendar Grey April 13, 2013
Scroller Suse
Addressing key vulnerabilities is essential for the SUSE Linux kernel to bolster both security and reliability.
An update that solves 6 vulnerabilities and has 15 fixes is An update that solves 6 vulnerabilities and has 15 fixes is An update that solves 6 vulnerabilities and has 15 fixes is ...

Summary

This Linux kernel update fixes various security issues and bugs in the SUSE Linux Enterprise 10 SP4 kernel. The following security issues have been fixed: * CVE-2013-0871: A race condition in ptrace(2) could be used by local attackers to crash the kernel and/or execute code in kernel context. * CVE-2013-0160: Avoid side channel information leaks from the ptys via ptmx, which allowed local attackers to guess keypresses. * CVE-2012-4530: Avoid leaving bprm->interp on the stack which might have leaked information from the kernel to userland attackers. * CVE-2013-0268: The msr_open function in arch/x86/kernel/msr.c in the Linux kernel allowed local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c. *

References

#742111 #765687 #769093 #770980 #776370 #781485

#785101 #786013 #787272 #789012 #790236 #792697

#795075 #795335 #797175 #799611 #800280 #801178

#802642 #804154 #809692

Cross- CVE-2012-4530 CVE-2013-0160 CVE-2013-0216

CVE-2013-0231 CVE-2013-0268 CVE-2013-0871

Affected Products:

SUSE Linux Enterprise Server 10 SP4

SUSE Linux Enterprise Desktop 10 SP4

SLE SDK 10 SP4

https://www.suse.com/security/cve/CVE-2012-4530.html

https://www.suse.com/security/cve/CVE-2013-0160.html

https://www.suse.com/security/cve/CVE-2013-0216.html

https://www.suse.com/security/cve/CVE-2013-0231.html

https://www.suse.com/security/cve/CVE-2013-0268.html

https://www.suse.com/security/cve/CVE-2013-0871.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:0674-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.