Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 550
Alerts This Week
Warning Icon 1 550

SUSE: 2015:1426-1 Important: KVM Buffer Overflow and Code Execution

suse
Calendar Grey August 21, 2015
Scroller Suse
SUSE Security Update for libvirt addresses vital vulnerabilities. Important: patches for remote code execution and memory corruption.
An update that fixes two vulnerabilities is now available

Summary

kvm was updated to fix two security issues. The following vulnerabilities were fixed: - CVE-2015-5154: Host code execution via IDE subsystem CD-ROM (bsc#938344). - CVE-2015-3209: Fix buffer overflow in pcnet emulation (bsc#932770). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP2-LTSS: zypper in -t patch slessp2-kvm-12041=1 - SUSE Linux Enterprise Debuginfo 11-SP2: zypper in -t patch dbgsp2-kvm-12041=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11-SP2-LTSS (i586 x86_64): kvm-0.15.1-0.32.2 - SUSE Linux Enterprise Debuginfo 11-SP2 (i586 x86_64): kvm-debuginfo-0.15.1-0.32.2 kvm-debugsource-0.15.1-0.32.2

References

#932770 #938344

Cross- CVE-2015-3209 CVE-2015-5154

Affected Products:

SUSE Linux Enterprise Server 11-SP2-LTSS

SUSE Linux Enterprise Debuginfo 11-SP2

https://www.suse.com/security/cve/CVE-2015-3209.html

https://www.suse.com/security/cve/CVE-2015-5154.html

https://bugzilla.suse.com/932770

https://bugzilla.suse.com/938344

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1426-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.