Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

SUSE: 2015:1156-1 Important: Xen Fixes Denial of Service Threats

suse
Calendar Grey June 29, 2015
Dist Suse Esm H88
SUSE Patch Update for OpenSSL resolves several high-priority vulnerabilities. Prompt application is essential to maintain system integrity.
An update that fixes 6 vulnerabilities is now available

Summary

Xen was updated to fix six security issues: * CVE-2015-4103: Potential unintended writes to host MSI message data field via qemu. (XSA-128, bsc#931625) * CVE-2015-4104: PCI MSI mask bits inadvertently exposed to guests. (XSA-129, bsc#931626) * CVE-2015-4105: Guest triggerable qemu MSI-X pass-through error messages. (XSA-130, bsc#931627) * CVE-2015-4106: Unmediated PCI register access in qemu. (XSA-131, bsc#931628) * CVE-2015-3209: heap overflow in qemu pcnet controller allowing guest to host escape. (XSA-135, bsc#932770) * CVE-2015-4164: DoS through iret hypercall handler. (XSA-136, bsc#932996) Security Issues: * CVE-2015-4103 * CVE-2015-4104

References

#931625 #931626 #931627 #931628 #932770 #932996

Cross- CVE-2015-3209 CVE-2015-4103 CVE-2015-4104

CVE-2015-4105 CVE-2015-4106 CVE-2015-4164

Affected Products:

SUSE Linux Enterprise Server 11 SP1 LTSS

https://www.suse.com/security/cve/CVE-2015-3209.html

https://www.suse.com/security/cve/CVE-2015-4103.html

https://www.suse.com/security/cve/CVE-2015-4104.html

https://www.suse.com/security/cve/CVE-2015-4105.html

https://www.suse.com/security/cve/CVE-2015-4106.html

https://www.suse.com/security/cve/CVE-2015-4164.html

https://bugzilla.suse.com/show_bug.cgi?id=931625

https://bugzilla.suse.com/show_bug.cgi?id=931626

https://bugzilla.suse.com/show_bug.cgi?id=931627

https://bugzilla.suse.com/show_bug.cgi?id=931628

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1156-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here