Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

SUSE Linux Enterprise 10 SP4 LTSS: 2014:0411-1 Important: Xen DoS

suse
Calendar Grey March 20, 2014
Scroller Suse
Important SUSE security update for Xen addresses 11 critical issues ensuring system stability.
An update that fixes 11 vulnerabilities is now available

Summary

The SUSE Linux Enterprise Server 10 Service Pack 4 LTSS Xen hypervisor and toolset have been updated to fix various security issues. The following security issues have been addressed: * XSA-82: CVE-2013-6885: The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue. (bnc#853049) * XSA-76: CVE-2013-4554: Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2. (bnc#849668)

References

#787163 #813673 #813677 #823011 #840592 #842511

#848657 #849668 #853049

Cross- CVE-2012-4544 CVE-2013-1917 CVE-2013-1920

CVE-2013-2194 CVE-2013-2195 CVE-2013-2196

CVE-2013-4355 CVE-2013-4368 CVE-2013-4494

CVE-2013-4554 CVE-2013-6885

Affected Products:

SUSE Linux Enterprise Server 10 SP4 LTSS

https://www.suse.com/security/cve/CVE-2012-4544.html

https://www.suse.com/security/cve/CVE-2013-1917.html

https://www.suse.com/security/cve/CVE-2013-1920.html

https://www.suse.com/security/cve/CVE-2013-2194.html

https://www.suse.com/security/cve/CVE-2013-2195.html

https://www.suse.com/security/cve/CVE-2013-2196.html

https://www.suse.com/security/cve/CVE-2013-4355.html

https://www.suse.com/security/cve/CVE-2013-4368.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0411-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.