Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE: 2014:0623-1 Important: KVM Buffer Overflow Threats Fixed

suse
Calendar Grey May 8, 2014
Scroller Suse
SUSE Security Patch: KVM addresses several critical vulnerabilities. Upgrade now to enhance the security posture of your SUSE environment.
An update that fixes 9 vulnerabilities is now available

Summary

The QEMU embedded within KVM received various security fixes. Various issues in the block layer have been fixed: * A virtio security issue in config io space handling (CVE-2013-2016). * A SCSI report LUNs buffer overflow (CVE-2013-4344). * A buffer overflow in the QEMU USB stack (CVE-2013-4541). Security Issue references: * CVE-2013-2016 * CVE-2013-4344 * CVE-2013-4541 * CVE-2014-0142 * CVE-2014-0143 * CVE-2014-0144

References

#812983 #817593 #842006 #864802 #870439

Cross- CVE-2013-2016 CVE-2013-4344 CVE-2013-4541

CVE-2014-0142 CVE-2014-0143 CVE-2014-0144

CVE-2014-0145 CVE-2014-0146 CVE-2014-0147

Affected Products:

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2013-2016.html

https://www.suse.com/security/cve/CVE-2013-4344.html

https://www.suse.com/security/cve/CVE-2013-4541.html

https://www.suse.com/security/cve/CVE-2014-0142.html

https://www.suse.com/security/cve/CVE-2014-0143.html

https://www.suse.com/security/cve/CVE-2014-0144.html

https://www.suse.com/security/cve/CVE-2014-0145.html

https://www.suse.com/security/cve/CVE-2014-0146.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:0623-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.