Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

SUSE 10 SP4: 2015:1643-1 Important: Multiple Xen Threats

suse
Calendar Grey September 25, 2015
Scroller Suse
SUSE Linux has issued a patch for four serious vulnerabilities in the Xen hypervisor, providing information on each issue's severity and references for more details
An update that fixes four vulnerabilities is now available

Summary

Xen was updated to fix the following security issues: * CVE-2015-5154: Host code execution via IDE subsystem CD-ROM. (bsc#938344) * CVE-2015-3209: Heap overflow in QEMU's pcnet controller allowing guest to host escape. (bsc#932770) * CVE-2015-4164: DoS through iret hypercall handler. (bsc#932996) * CVE-2015-5165: QEMU leak of uninitialized heap memory in rtl8139 device model. (XSA-140, bsc#939712) Security Issues: * CVE-2015-5154 * CVE-2015-3209 * CVE-2015-4164 * CVE-2015-5165 Package List:

References

#932770 #932996 #938344 #939712

Cross- CVE-2015-3209 CVE-2015-4164 CVE-2015-5154

CVE-2015-5165

Affected Products:

SUSE Linux Enterprise Server 10 SP4 LTSS

https://www.suse.com/security/cve/CVE-2015-3209.html

https://www.suse.com/security/cve/CVE-2015-4164.html

https://www.suse.com/security/cve/CVE-2015-5154.html

https://www.suse.com/security/cve/CVE-2015-5165.html

https://bugzilla.suse.com/show_bug.cgi?id=932770

https://bugzilla.suse.com/show_bug.cgi?id=932996

https://bugzilla.suse.com/show_bug.cgi?id=938344

https://bugzilla.suse.com/show_bug.cgi?id=939712

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1643-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.