Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE 12: SUSE-SU-2015:1519-1 Important: QEMU Heap Overflow

suse
Calendar Grey September 9, 2015
Dist Suse Esm H88
The recent patch for qemu addresses critical vulnerabilities, including buffer overflow and filename leakage concerns on SUSE systems, enhancing overall security.
An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now avai...

Summary

qemu was updated to fix two security issues and augments one non-security bug fix. The following vulnerabilities were fixed: * CVE-2015-3209: heap overflow in qemu pcnet controller allowing guest to host escape (XSA-135) (bsc#932770) * CVE-2015-4037: Avoid predictable directory name for smb config (bsc#932267) The fix for the following non-security bug was improved: * bsc#893892: Use improved upstream patch for display issue affecting installs of SLES 11 VMs on SLES 12 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12: zypper in -t patch SUSE-SLE-SERVER-12-2015-509=1 - SUSE Linux Enterprise Desktop 12: zypper in -t patch SUSE-SLE-DESKTOP-12-2015-509=1

References

#893892 #932267 #932770

Cross- CVE-2015-3209 CVE-2015-4037

Affected Products:

SUSE Linux Enterprise Server 12

SUSE Linux Enterprise Desktop 12

https://www.suse.com/security/cve/CVE-2015-3209.html

https://www.suse.com/security/cve/CVE-2015-4037.html

https://bugzilla.suse.com/show_bug.cgi?id=893892

https://bugzilla.suse.com/show_bug.cgi?id=932267

https://bugzilla.suse.com/show_bug.cgi?id=932770

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1519-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here