Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE Linux 10 SP3: 2014:0470-1 Important: Denial Of Service Risks

suse
Calendar Grey April 1, 2014
Scroller Suse
A significant security patch from SUSE for Xen resolves 15 security flaws. Remember to restart your system after applying the update to ensure full protection.
An update that fixes 15 vulnerabilities is now available

Summary

The SUSE Linux Enterprise 10 Service Pack 3 LTSS Xen hypervisor and toolset have been updated to fix various security issues: The following security issues have been addressed: * XSA-20: CVE-2012-4535: Xen 3.4 through 4.2, and possibly earlier versions, allows local guest OS administrators to cause a denial of service (Xen infinite loop and physical CPU consumption) by setting a VCPU with an "inappropriate deadline". (bnc#786516) * XSA-22: CVE-2012-4537: Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS administrators to cause a denial of service (memory consumption and assertion failure), aka "Memory mapping failure DoS vulnerability". (bnc#786517) *

References

#786516 #786517 #787163 #789950 #789951 #813673

#813677 #823011 #840592 #842511 #848657 #849668

#853049

Cross- CVE-2012-4535 CVE-2012-4537 CVE-2012-4544

CVE-2012-5513 CVE-2012-5515 CVE-2013-1917

CVE-2013-1920 CVE-2013-2194 CVE-2013-2195

CVE-2013-2196 CVE-2013-4355 CVE-2013-4368

CVE-2013-4494 CVE-2013-4554 CVE-2013-6885

Affected Products:

SUSE Linux Enterprise Server 10 SP3 LTSS

https://www.suse.com/security/cve/CVE-2012-4535.html

https://www.suse.com/security/cve/CVE-2012-4537.html

https://www.suse.com/security/cve/CVE-2012-4544.html

https://www.suse.com/security/cve/CVE-2012-5513.html

https://www.suse.com/security/cve/CVE-2012-5515.html

https://www.suse.com/security/cve/CVE-2013-1917.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0470-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.