Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

SUSE 11 SP1 LTSS: 2015:0940-1 Important: Xen Buffer Overflow and Leak

suse
Calendar Grey May 26, 2015
Dist Suse Esm H88
Crucial SUSE patch addresses two vulnerabilities in Xen associated with buffer overflow and data exposure.
An update that fixes two vulnerabilities is now available

Summary

Xen was updated to fix two security issues: * CVE-2015-3456: A buffer overflow in the floppy drive emulation, which could be used to carry out denial of service attacks or potential code execution against the host. This vulnerability is also known as VENOM. * CVE-2015-3340: An information leak through XEN_DOMCTL_gettscinfo(). (XSA-132) Security Issues: * CVE-2015-3456 * CVE-2015-3340 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP1 LTSS: zypper in -t patch slessp1-xen=10684 To bring your system up-to-date, use "zypper patch".

References

#927967 #929339

Cross- CVE-2015-3340 CVE-2015-3456

Affected Products:

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2015-3340.html

https://www.suse.com/security/cve/CVE-2015-3456.html

https://bugzilla.suse.com/927967

https://bugzilla.suse.com/929339

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0940-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here