Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE 11-SP3: 2016:1745-1 Important: Xen Buffer Overflow Risk

suse
Calendar Grey July 6, 2016
Dist Suse Esm H88
A significant update from SUSE resolves 36 vulnerabilities related to xen, bolstering system defenses against multiple potential risks.
An update that solves 35 vulnerabilities and has 5 fixes is An update that solves 35 vulnerabilities and has 5 fixes is An update that solves 35 vulnerabilities and has 5 fixes is ...

Summary

xen was updated to fix 36 security issues. These security issues were fixed: - CVE-2013-4527: Buffer overflow in hw/timer/hpet.c might have allowed remote attackers to execute arbitrary code via vectors related to the number of timers (bnc#864673). - CVE-2013-4529: Buffer overflow in hw/pci/pcie_aer.c allowed remote attackers to cause a denial of service and possibly execute arbitrary code via a large log_num value in a savevm image (bnc#864678). - CVE-2013-4530: Buffer overflow in hw/ssi/pl022.c allowed remote attackers to cause a denial of service or possibly execute arbitrary code via crafted tx_fifo_head and rx_fifo_head values in a savevm image (bnc#864682). - CVE-2013-4533: Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c allowed remote attackers to cause a denial of service or

References

#864391 #864655 #864673 #864678 #864682 #864769

#864805 #864811 #877642 #897654 #901508 #902737

#928393 #945404 #945989 #954872 #956829 #957162

#957988 #958007 #958009 #958491 #958523 #959005

#959695 #959928 #960707 #960725 #960861 #960862

#961332 #961691 #963782 #965315 #965317 #967012

#967013 #967630 #967969 #969350

Cross- CVE-2013-4527 CVE-2013-4529 CVE-2013-4530

CVE-2013-4533 CVE-2013-4534 CVE-2013-4537

CVE-2013-4538 CVE-2013-4539 CVE-2014-0222

CVE-2014-3640 CVE-2014-3689 CVE-2014-7815

CVE-2014-9718 CVE-2015-5278 CVE-2015-6855

CVE-2015-7512 CVE-2015-8345 CVE-2015-8504

CVE-2015-8550 CVE-2015-8554 CVE-2015-8555

CVE-2015-8558 CVE-2015-8743 CVE-2015-8745

CVE-2016-1568 CVE-2016-1570 CVE-2016-1571

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:1745-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here