Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

SUSE: 2017:0789-1 Critical: Qemu Security Flaw & Command Exploits

suse
Calendar Grey February 15, 2016
Dist Suse Esm H88
Ubuntu Security Update addresses critical vulnerabilities in libcurl, improving overall system integrity with vital corrections and enhancements.
An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now avai...

Summary

This update fixes the following security issues: - Enforce receive packet size, thus eliminating buffer overflow and potential security issue. (bsc#957162 CVE-2015-7512) - Infinite loop in processing command block list. CVE-2015-8345 (bsc#956829): This update also fixes a non-security bug: - Due to space restrictions in limited bios data areas, don't create mptable if vcpu count is "high" (ie more than ~19). (bsc#954864) (No supported guests are negatively impacted by this change, which is taken from upstream seabios) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP1: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2016-263=1 - SUSE Linux Enterprise Desktop 12-SP1:

References

#954864 #956829 #957162

Cross- CVE-2015-7512 CVE-2015-8345

Affected Products:

SUSE Linux Enterprise Server 12-SP1

SUSE Linux Enterprise Desktop 12-SP1

https://www.suse.com/security/cve/CVE-2015-7512.html

https://www.suse.com/security/cve/CVE-2015-8345.html

https://bugzilla.suse.com/954864

https://bugzilla.suse.com/956829

https://bugzilla.suse.com/957162

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0459-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here