Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE Security Advisory 2015:0929-1 Addresses Important KVM DoS Risks

suse
Calendar Grey May 22, 2015
Scroller Suse
SUSE Security Patch for KVM addresses severe vulnerabilities, guaranteeing system integrity and reliability through vital upgrades.
An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now available

Summary

KVM was updated to fix the following security issues: * CVE-2015-3456: Buffer overflow in the floppy drive emulation, which could be used to carry out denial of service attacks or potential code execution against the host. This vulnerability is also known as VENOM. * CVE-2014-0222: Integer overflow in the qcow_open function in block/qcow.c in QEMU allowed remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image. * CVE-2014-0223: Integer overflow in the qcow_open function in block/qcow.c in QEMU allowed local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read. Security Issues: * CVE-2015-3456

References

#877642 #877645 #929339

Cross- CVE-2014-0222 CVE-2014-0223 CVE-2015-3456

Affected Products:

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2014-0222.html

https://www.suse.com/security/cve/CVE-2014-0223.html

https://www.suse.com/security/cve/CVE-2015-3456.html

https://bugzilla.suse.com/877642

https://bugzilla.suse.com/877645

https://bugzilla.suse.com/929339

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0929-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.