Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE: 2014:0446-1 Important Repair for Xen Denial of Service Issue

suse
Calendar Grey March 25, 2014
Scroller Suse
Red Hat issues critical patch for OpenShift tackling 53 discovered vulnerabilities. Maintain security integrity with the newest updates.
An update that fixes 47 vulnerabilities is now available

Summary

The SUSE Linux Enterprise Server 11 Service Pack 1 LTSS Xen hypervisor and toolset have been updated to fix various security issues and some bugs. The following security issues have been addressed: * XSA-84: CVE-2014-1894: Xen 3.2 (and presumably earlier) exhibit both problems with the overflow issue being present for more than just the suboperations listed above. (bnc#860163) * XSA-84: CVE-2014-1892 CVE-2014-1893: Xen 3.3 through 4.1, while not affected by the above overflow, have a different overflow issue on FLASK_{GET,SET}BOOL and expose unreasonably large memory allocation to aribitrary guests. (bnc#860163) * XSA-84: CVE-2014-1891: The FLASK_{GET,SET}BOOL, FLASK_USER and FLASK_CONTEXT_TO_SID suboperations of the flask hypercall are vulnerable to an integer overflow on

References

#777628 #777890 #779212 #786516 #786517 #786519

#786520 #787163 #789944 #789945 #789948 #789950

#789951 #794316 #797031 #797523 #800275 #805094

#813673 #813675 #813677 #816156 #816159 #816163

#819416 #820917 #820919 #823011 #823608 #826882

#831120 #839596 #839618 #840592 #841766 #842511

#848657 #849667 #849668 #853049 #860163

Cross- CVE-2006-1056 CVE-2007-0998 CVE-2012-3497

CVE-2012-4411 CVE-2012-4535 CVE-2012-4537

CVE-2012-4538 CVE-2012-4539 CVE-2012-4544

CVE-2012-5510 CVE-2012-5511 CVE-2012-5513

CVE-2012-5514 CVE-2012-5515 CVE-2012-5634

CVE-2012-6075 CVE-2012-6333 CVE-2013-0153

CVE-2013-0154 CVE-2013-1432 CVE-2013-1442

CVE-2013-1917 CVE-2013-1918 CVE-2013-1919

CVE-2013-1920 CVE-2013-1952 CVE-2013-1964

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0446-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.