Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE 11-SP4: 2015:1895-1 Critical: QEMU Buffer Overflow Vulnerability

suse
Calendar Grey November 3, 2015
Dist Suse Esm H88
Critical announcement for SUSE Linux tackling various challenges in xen. Apply updates to boost system integrity and performance.
An update that solves 8 vulnerabilities and has 9 fixes is An update that solves 8 vulnerabilities and has 9 fixes is An update that solves 8 vulnerabilities and has 9 fixes is now...

Summary

xen was updated to version 4.4.3 to fix nine security issues. These security issues were fixed: - CVE-2015-4037: The slirp_smb function in net/slirp.c created temporary files with predictable names, which allowed local users to cause a denial of service (instantiation failure) by creating /tmp/qemu-smb.*-* files before the program (bsc#932267). - CVE-2014-0222: Integer overflow in the qcow_open function allowed remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image (bsc#877642). - CVE-2015-7835: Uncontrolled creation of large page mappings by PV guests (bsc#950367). - CVE-2015-7311: libxl in Xen did not properly handle the readonly flag on disks when using the qemu-xen device model, which allowed local guest users to write to a read-only disk image (bsc#947165).

References

#877642 #901488 #907514 #910258 #918984 #923967

#932267 #944463 #944697 #945167 #947165 #949138

#949549 #950367 #950703 #950705 #950706

Cross- CVE-2014-0222 CVE-2015-4037 CVE-2015-5239

CVE-2015-6815 CVE-2015-7311 CVE-2015-7835

CVE-2015-7969 CVE-2015-7971

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Desktop 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP4

https://www.suse.com/security/cve/CVE-2014-0222.html

https://www.suse.com/security/cve/CVE-2015-4037.html

https://www.suse.com/security/cve/CVE-2015-5239.html

https://www.suse.com/security/cve/CVE-2015-6815.html

https://www.suse.com/security/cve/CVE-2015-7311.html

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1894-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here