Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2016:0658-1 Important: Xen DoS and Buffer Overflow Threat

suse
Calendar Grey March 4, 2016
Dist Suse Esm H88
Addresses 13 significant vulnerabilities in Xen for SUSE Linux. A reboot is necessary following this critical update implementation.
An update that fixes 13 vulnerabilities is now available

Summary

Xen was updated to fix the following vulnerabilities: * CVE-2014-0222: Qcow1 L2 table size integer overflows (bsc#877642) * CVE-2015-4037: Insecure temporary file use in /net/slirp.c (bsc#932267) * CVE-2015-5239: Integer overflow in vnc_client_read() and protocol_client_msg() (bsc#944463) * CVE-2015-7504: Heap buffer overflow vulnerability in pcnet emulator (XSA-162, bsc#956411) * CVE-2015-7971: Some pmu and profiling hypercalls log without rate limiting (XSA-152, bsc#950706) * CVE-2015-8104: Guest to host DoS by triggering an infinite loop in microcode via #DB exception (bsc#954405) * CVE-2015-5307: Guest to host DOS by intercepting #AC (XSA-156, bsc#953527) * CVE-2015-8339: XENMEM_exchange error handling issues (XSA-159, bsc#956408)

References

#877642 #932267 #944463 #950706 #953527 #954405

#956408 #956411 #957988 #958009 #958493 #958523

#962360

Cross- CVE-2014-0222 CVE-2015-4037 CVE-2015-5239

CVE-2015-5307 CVE-2015-7504 CVE-2015-7512

CVE-2015-7971 CVE-2015-8104 CVE-2015-8339

CVE-2015-8340 CVE-2015-8504 CVE-2015-8550

CVE-2015-8555

Affected Products:

SUSE Linux Enterprise Server 10 SP4 LTSS

https://www.suse.com/security/cve/CVE-2014-0222.html

https://www.suse.com/security/cve/CVE-2015-4037.html

https://www.suse.com/security/cve/CVE-2015-5239.html

https://www.suse.com/security/cve/CVE-2015-5307.html

https://www.suse.com/security/cve/CVE-2015-7504.html

https://www.suse.com/security/cve/CVE-2015-7512.html

https://www.suse.com/security/cve/CVE-2015-7971.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:0658-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here