Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2015:1152-1 important: KVM Heap Overflow and Security Fix

suse
Calendar Grey June 26, 2015
Dist Suse Esm H88
SUSE has published a security bulletin concerning KVM, highlighting serious vulnerabilities within SUSE Linux.
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is ...

Summary

KVM was updated to fix two security issues: * CVE-2015-3209: Heap overflow in qemu pcnet controller allowing guest to host escape. (bsc#932770) * CVE-2015-4037: Predictable directory names for smb configuration. (bsc#932267) Security Issues: * CVE-2015-3209 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP3: zypper in -t patch slessp3-kvm=10747 - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-kvm=10747 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP3 (i586 s390x x86_64) [New Version: 1.4.2]: kvm-1.4.2-0.22.31.1

References

#932267 #932770

Cross- CVE-2015-3209

Affected Products:

SUSE Linux Enterprise Server 11 SP3

SUSE Linux Enterprise Desktop 11 SP3

https://www.suse.com/security/cve/CVE-2015-3209.html

https://bugzilla.suse.com/show_bug.cgi?id=932267

https://bugzilla.suse.com/show_bug.cgi?id=932770

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1152-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here