An update that contains security fixes can now be installed. . SUSE Security Update: Security update for xen ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2166-1 Rating: important References: #1172356 #1174543 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for xen fixes the following issues: - bsc#1174543 - secure boot related fixes - bsc#1172356 - Not able to hot-plug NIC via virt-manager, asks to attach on next reboot while it should be live attached Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-2166=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-2166=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 x86_64): xen-debugsource-4.12.3_06-3.21.1 xen-devel-4.12.3_06-3.21.1 - SUSE Linux Enterprise Server 12-SP5 (x86_64): xen-4.12.3_06-3.21.1 xen-debugsource-4.12.3_06-3.21.1 xen-doc-html-4.12.3_06-3.21.1 xen-libs-32bit-4.12.3_06-3.21.1 xen-libs-4.12.3_06-3.21.1 xen-libs-debuginfo-32bit-4.12.3_06-3.21.1 xen-libs-debuginfo-4.12.3_06-3.21.1 xen-tools-4.12.3_06-3.21.1 xen-tools-debuginfo-4.12.3_06-3.21.1 xen-tools-domU-4.12.3_06-3.21.1 xen-tools-domU-debuginfo-4.12.3_06-3.21.1 References: https://bugzilla.suse.com/1172356 https://bugzilla.suse.com/1174543 _______________________________________________ sle-security-updates mailing list
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for dpdk ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1430-1 Rating: important References: #1171477 #1171925 #1171930 Cross-References: CVE-2019-14818 CVE-2020-10722 CVE-2020-10723 Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Server 12-SP4 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for dpdk to 17.11.7 fixes the following issues: Security issues fixed: - CVE-2020-10722: Fixed an integer overflow in vhost_user_set_log_base() (bsc#1171477 bsc#1171930). - CVE-2020-10723: Fixed an integer truncation in vhost_user_check_and_alloc_queue_pair() (bsc#1171477). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2020-1430=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2020-1430=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le x86_64): dpdk-debuginfo-17.11.7-5.6.2 dpdk-debugsource-17.11.7-5.6.2 dpdk-devel-17.11.7-5.6.2 dpdk-devel-debuginfo-17.11.7-5.6.2 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64): dpdk-thunderx-debuginfo-17.11.7-5.6.2 dpdk-thunderx-debugsource-17.11.7-5.6.2 dpdk-thunderx-devel-17.11.7-5.6.2 dpdk-thunderx-devel-debuginfo-17.11.7-5.6.2 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le x86_64): dpdk-17.11.7-5.6.2 dpdk-debuginfo-17.11.7-5.6.2 dpdk-debugsource-17.11.7-5.6.2 dpdk-tools-17.11.7-5.6.2 dpdk-tools-debuginfo-17.11.7-5.6.2 libdpdk-17_11-17.11.7-5.6.2 libdpdk-17_11-debuginfo-17.11.7-5.6.2 - SUSE Linux Enterprise Server 12-SP4 (aarch64): dpdk-thunderx-17.11.7-5.6.2 dpdk-thunderx-debuginfo-17.11.7-5.6.2 dpdk-thunderx-debugsource-17.11.7-5.6.2 dpdk-thunderx-kmp-default-17.11.7_k4.12.14_95.51-5.6.2 dpdk-thunderx-kmp-default-debuginfo-17.11.7_k4.12.14_95.51-5.6.2 - SUSE Linux Enterprise Server 12-SP4 (x86_64): dpdk-kmp-default-17.11.7_k4.12.14_95.51-5.6.2 dpdk-kmp-default-debuginfo-17.11.7_k4.12.14_95.51-5.6.2 References: https://www.suse.com/security/cve/CVE-2019-14818.html https://www.suse.com/security/cve/CVE-2020-10722.html https://www.suse.com/security/cve/CVE-2020-10723.html https://bugzilla.suse.com/1171477 https://bugzilla.suse.com/1171925 https://bugzilla.suse.com/1171930 _______________________________________________ sle-security-updates mailing list
An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. SUSE Security Update: Security update for PHP 5.3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2015:0436-1 Rating: important References: #917150 #918768 Cross-References: CVE-2013-6501 CVE-2014-9652 Affected Products: SUSE Linux Enterprise Software Development Kit 11 SP3 SUSE Linux Enterprise Server 11 SP3 for VMware SUSE Linux Enterprise Server 11 SP3 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: php5 has been updated to fix two security issues: * CVE-2014-9652: Out of bounds read in mconvert() (bnc#917150). * CVE-2015-0273: Use after free vulnerability in unserialize() with DateTimeZone (bnc#918768). Security Issues: * CVE-2014-9652 * CVE-2013-6501 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP3: zypper in -t patch sdksp3-apache2-mod_php53=10370 - SUSE Linux Enterprise Server 11 SP3 for VMware: zypper in -t patch slessp3-apache2-mod_php53=10370 - SUSE Linux Enterprise Server 11 SP3: zypper in -t patch slessp3-apache2-mod_php53=10370 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP3 (i586 ia64 ppc64 s390x x86_64): php53-devel-5.3.17-0.35.2 php53-imap-5.3.17-0.35.2 php53-posix-5.3.17-0.35.2 php53-readline-5.3.17-0.35.2 php53-sockets-5.3.17-0.35.2 php53-sqlite-5.3.17-0.35.2 php53-tidy-5.3.17-0.35.2 - SUSE Linux Enterprise Server 11 SP3 for VMware (i586 x86_64): apache2-mod_php53-5.3.17-0.35.2 php53-5.3.17-0.35.2 php53-bcmath-5.3.17-0.35.2 php53-bz2-5.3.17-0.35.2 php53-calendar-5.3.17-0.35.2 php53-ctype-5.3.17-0.35.2 php53-curl-5.3.17-0.35.2 php53-dba-5.3.17-0.35.2 php53-dom-5.3.17-0.35.2 php53-exif-5.3.17-0.35.2 php53-fastcgi-5.3.17-0.35.2 php53-fileinfo-5.3.17-0.35.2 php53-ftp-5.3.17-0.35.2 php53-gd-5.3.17-0.35.2 php53-gettext-5.3.17-0.35.2 php53-gmp-5.3.17-0.35.2 php53-iconv-5.3.17-0.35.2 php53-intl-5.3.17-0.35.2 php53-json-5.3.17-0.35.2 php53-ldap-5.3.17-0.35.2 php53-mbstring-5.3.17-0.35.2 php53-mcrypt-5.3.17-0.35.2 php53-mysql-5.3.17-0.35.2 php53-odbc-5.3.17-0.35.2 php53-openssl-5.3.17-0.35.2 php53-pcntl-5.3.17-0.35.2 php53-pdo-5.3.17-0.35.2 php53-pear-5.3.17-0.35.2 php53-pgsql-5.3.17-0.35.2 php53-pspell-5.3.17-0.35.2 php53-shmop-5.3.17-0.35.2 php53-snmp-5.3.17-0.35.2 php53-soap-5.3.17-0.35.2 php53-suhosin-5.3.17-0.35.2 php53-sysvmsg-5.3.17-0.35.2 php53-sysvsem-5.3.17-0.35.2 php53-sysvshm-5.3.17-0.35.2 php53-tokenizer-5.3.17-0.35.2 php53-wddx-5.3.17-0.35.2 php53-xmlreader-5.3.17-0.35.2 php53-xmlrpc-5.3.17-0.35.2 php53-xmlwriter-5.3.17-0.35.2 php53-xsl-5.3.17-0.35.2 php53-zip-5.3.17-0.35.2 php53-zlib-5.3.17-0.35.2 - SUSE Linux Enterprise Server 11 SP3 (i586 ia64 ppc64 s390x x86_64): apache2-mod_php53-5.3.17-0.35.2 php53-5.3.17-0.35.2 php53-bcmath-5.3.17-0.35.2 php53-bz2-5.3.17-0.35.2 php53-calendar-5.3.17-0.35.2 php53-ctype-5.3.17-0.35.2 php53-curl-5.3.17-0.35.2 php53-dba-5.3.17-0.35.2 php53-dom-5.3.17-0.35.2 php53-exif-5.3.17-0.35.2 php53-fastcgi-5.3.17-0.35.2 php53-fileinfo-5.3.17-0.35.2 php53-ftp-5.3.17-0.35.2 php53-gd-5.3.17-0.35.2 php53-gettext-5.3.17-0.35.2 php53-gmp-5.3.17-0.35.2 php53-iconv-5.3.17-0.35.2 php53-intl-5.3.17-0.35.2 php53-json-5.3.17-0.35.2 php53-ldap-5.3.17-0.35.2 php53-mbstring-5.3.17-0.35.2 php53-mcrypt-5.3.17-0.35.2 php53-mysql-5.3.17-0.35.2 php53-odbc-5.3.17-0.35.2 php53-openssl-5.3.17-0.35.2 php53-pcntl-5.3.17-0.35.2 php53-pdo-5.3.17-0.35.2 php53-pear-5.3.17-0.35.2 php53-pgsql-5.3.17-0.35.2 php53-pspell-5.3.17-0.35.2 php53-shmop-5.3.17-0.35.2 php53-snmp-5.3.17-0.35.2 php53-soap-5.3.17-0.35.2 php53-suhosin-5.3.17-0.35.2 php53-sysvmsg-5.3.17-0.35.2 php53-sysvsem-5.3.17-0.35.2 php53-sysvshm-5.3.17-0.35.2 php53-tokenizer-5.3.17-0.35.2 php53-wddx-5.3.17-0.35.2 php53-xmlreader-5.3.17-0.35.2 php53-xmlrpc-5.3.17-0.35.2 php53-xmlwriter-5.3.17-0.35.2 php53-xsl-5.3.17-0.35.2 php53-zip-5.3.17-0.35.2 php53-zlib-5.3.17-0.35.2 References: https://www.suse.com/security/cve/CVE-2013-6501.html https://www.suse.com/security/cve/CVE-2014-9652.html https://bugzilla.suse.com/show_bug.cgi?id=917150 https://bugzilla.suse.com/show_bug.cgi?id=918768 https://scc.suse.com:443/patches/ . SUSE Linux has released a vital security patch for PHP 5.3, targeting essential vulnerabilities. Safeguard your systems!. SUSE PHP Security, Software Update, Development Kit, Security Fix, Critical Issues. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.