Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE Linux 11 SP1 LTSS Advisory 2014:1138-1 Critical: DoS Security Fix

suse
Calendar Grey September 16, 2014
Scroller Suse
SUSE Security Update introduces essential kernel fix tackling 22 vulnerabilities aimed at improving system security and functionality.
An update that fixes 22 vulnerabilities is now available

Summary

The SUSE Linux Enterprise Server 11 SP1 LTSS received a roll up update to fix several security and non-security issues. The following security issues have been fixed: * CVE-2013-1860: Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted cdc-wdm USB device. (bnc#806431) * CVE-2013-4162: The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK

References

#794824 #806431 #831058 #854722 #856756 #871797

#877257 #879921 #880484 #881051 #882809 #883526

#883724 #883795 #884530 #885422 #885725 #887082

#889173 #892490

Cross- CVE-2013-1860 CVE-2013-4162 CVE-2013-7266

CVE-2013-7267 CVE-2013-7268 CVE-2013-7269

CVE-2013-7270 CVE-2013-7271 CVE-2014-0203

CVE-2014-3144 CVE-2014-3145 CVE-2014-3917

CVE-2014-4508 CVE-2014-4652 CVE-2014-4653

CVE-2014-4654 CVE-2014-4655 CVE-2014-4656

CVE-2014-4667 CVE-2014-4699 CVE-2014-4943

CVE-2014-5077

Affected Products:

SUSE Linux Enterprise Server 11 SP1 LTSS

SLE 11 SERVER Unsupported Extras

https://www.suse.com/security/cve/CVE-2013-1860.html

https://www.suse.com/security/cve/CVE-2013-4162.html

https://www.suse.com/security/cve/CVE-2013-7266.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1138-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.