Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE 11 SP2 LTSS Security Update: 2014:0372-1 Important Xen Issues

suse
Calendar Grey March 14, 2014
Scroller Suse
SUSE Security Patch for Xen resolves 10 critical vulnerabilities, addressing a range of safety issues along with recommended measures.
An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata ...

Summary

The SUSE Linux Enterprise Server 11 Service Pack 2 LTSS Xen hypervisor and toolset has been updated to fix various security issues and several bugs. The following security issues have been addressed: * XSA-88: CVE-2014-1950: Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local users with access to management functions to cause a denial of service (heap corruption) and possibly gain privileges via unspecified vectors. (bnc#861256) * XSA-87: CVE-2014-1666: The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix

References

#831120 #833483 #842417 #846849 #848014 #849667

#849668 #853049 #860163 #860302 #861256

Cross- CVE-2013-2212 CVE-2013-4553 CVE-2013-4554

CVE-2013-6885 CVE-2014-1666 CVE-2014-1891

CVE-2014-1892 CVE-2014-1893 CVE-2014-1894

CVE-2014-1950

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

https://www.suse.com/security/cve/CVE-2013-2212.html

https://www.suse.com/security/cve/CVE-2013-4553.html

https://www.suse.com/security/cve/CVE-2013-4554.html

https://www.suse.com/security/cve/CVE-2013-6885.html

https://www.suse.com/security/cve/CVE-2014-1666.html

https://www.suse.com/security/cve/CVE-2014-1891.html

https://www.suse.com/security/cve/CVE-2014-1892.html

https://www.suse.com/security/cve/CVE-2014-1893.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0372-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.