You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa Xen

Sigurnosni nedostaci programskog paketa Xen

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LSU

SUSE Security Update: Security update for Xen
______________________________________________________________________________

Announcement ID: SUSE-SU-2015:0889-2
Rating: important
References: #929339
Cross-References: CVE-2015-3456
Affected Products:
SUSE Linux Enterprise Server 10 SP4 LTSS
______________________________________________________________________________

An update that fixes one vulnerability is now available.

Description:

Xen was updated to fix a buffer overflow in the floppy drive emulation,
which could be used to carry out denial of service attacks or potential
code execution against the host. This vulnerability is also known as
VENOM. (CVE-2015-3456)

Security Issues:

* CVE-2015-3456
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456>

Package List:

– SUSE Linux Enterprise Server 10 SP4 LTSS (i586 x86_64):

xen-3.2.3_17040_46-0.15.1
xen-devel-3.2.3_17040_46-0.15.1
xen-doc-html-3.2.3_17040_46-0.15.1
xen-doc-pdf-3.2.3_17040_46-0.15.1
xen-doc-ps-3.2.3_17040_46-0.15.1
xen-kmp-debug-3.2.3_17040_46_2.6.16.60_0.132.1-0.15.1
xen-kmp-default-3.2.3_17040_46_2.6.16.60_0.132.1-0.15.1
xen-kmp-kdump-3.2.3_17040_46_2.6.16.60_0.132.1-0.15.1
xen-kmp-smp-3.2.3_17040_46_2.6.16.60_0.132.1-0.15.1
xen-libs-3.2.3_17040_46-0.15.1
xen-tools-3.2.3_17040_46-0.15.1
xen-tools-domU-3.2.3_17040_46-0.15.1
xen-tools-ioemu-3.2.3_17040_46-0.15.1

– SUSE Linux Enterprise Server 10 SP4 LTSS (x86_64):

xen-libs-32bit-3.2.3_17040_46-0.15.1

– SUSE Linux Enterprise Server 10 SP4 LTSS (i586):

xen-kmp-bigsmp-3.2.3_17040_46_2.6.16.60_0.132.1-0.15.1
xen-kmp-kdumppae-3.2.3_17040_46_2.6.16.60_0.132.1-0.15.1
xen-kmp-vmi-3.2.3_17040_46_2.6.16.60_0.132.1-0.15.1
xen-kmp-vmipae-3.2.3_17040_46_2.6.16.60_0.132.1-0.15.1

References:

https://www.suse.com/security/cve/CVE-2015-3456.html
https://bugzilla.suse.com/929339
https://download.suse.com/patch/finder/?keywords=114b7cce479b39879add5cf1937e0e2d


To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org

SUSE Security Update: Security update for Xen
______________________________________________________________________________

Announcement ID: SUSE-SU-2015:0940-1
Rating: important
References: #927967 #929339
Cross-References: CVE-2015-3340 CVE-2015-3456
Affected Products:
SUSE Linux Enterprise Server 11 SP1 LTSS
______________________________________________________________________________

An update that fixes two vulnerabilities is now available.

Description:

Xen was updated to fix two security issues:

* CVE-2015-3456: A buffer overflow in the floppy drive emulation,
which could be used to carry out denial of service attacks or
potential code execution against the host. This vulnerability is
also known as VENOM.
* CVE-2015-3340: An information leak through XEN_DOMCTL_gettscinfo().
(XSA-132)

Security Issues:

* CVE-2015-3456
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456>
* CVE-2015-3340
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3340>

Patch Instructions:

To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

– SUSE Linux Enterprise Server 11 SP1 LTSS:

zypper in -t patch slessp1-xen=10684

To bring your system up-to-date, use “zypper patch”.

Package List:

– SUSE Linux Enterprise Server 11 SP1 LTSS (i586 x86_64):

xen-4.0.3_21548_18-0.21.1
xen-doc-html-4.0.3_21548_18-0.21.1
xen-doc-pdf-4.0.3_21548_18-0.21.1
xen-kmp-default-4.0.3_21548_18_2.6.32.59_0.19-0.21.1
xen-kmp-trace-4.0.3_21548_18_2.6.32.59_0.19-0.21.1
xen-libs-4.0.3_21548_18-0.21.1
xen-tools-4.0.3_21548_18-0.21.1
xen-tools-domU-4.0.3_21548_18-0.21.1

– SUSE Linux Enterprise Server 11 SP1 LTSS (i586):

xen-kmp-pae-4.0.3_21548_18_2.6.32.59_0.19-0.21.1

References:

https://www.suse.com/security/cve/CVE-2015-3340.html
https://www.suse.com/security/cve/CVE-2015-3456.html
https://bugzilla.suse.com/927967
https://bugzilla.suse.com/929339
https://download.suse.com/patch/finder/?keywords=aee7c643a4c4513e4350b80ada2e9e6f


To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org

SUSE Security Update: Security update for Xen
______________________________________________________________________________

Announcement ID: SUSE-SU-2015:0944-1
Rating: important
References: #910441 #927967 #929339
Cross-References: CVE-2015-3340 CVE-2015-3456
Affected Products:
SUSE Linux Enterprise Server 11 SP2 LTSS
______________________________________________________________________________

An update that solves two vulnerabilities and has one
errata is now available.

Description:

Xen was updated to fix two security issues and a bug:

* CVE-2015-3456: A buffer overflow in the floppy drive emulation,
which could be used to carry out denial of service attacks or
potential code execution against the host. This vulnerability is
also known as VENOM.
* CVE-2015-3340: Xen did not initialize certain fields, which allowed
certain remote service domains to obtain sensitive information from
memory via a (1) XEN_DOMCTL_gettscinfo or (2)
XEN_SYSCTL_getdomaininfolist request.
* An exception in setCPUAffinity when restoring guests. (bsc#910441)

Security Issues:

* CVE-2015-3456
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456>
* CVE-2015-3340
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3340>

Patch Instructions:

To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

– SUSE Linux Enterprise Server 11 SP2 LTSS:

zypper in -t patch slessp2-xen=10685

To bring your system up-to-date, use “zypper patch”.

Package List:

– SUSE Linux Enterprise Server 11 SP2 LTSS (i586 x86_64):

xen-devel-4.1.6_08-0.11.1
xen-kmp-default-4.1.6_08_3.0.101_0.7.29-0.11.1
xen-kmp-trace-4.1.6_08_3.0.101_0.7.29-0.11.1
xen-libs-4.1.6_08-0.11.1
xen-tools-domU-4.1.6_08-0.11.1

– SUSE Linux Enterprise Server 11 SP2 LTSS (x86_64):

xen-4.1.6_08-0.11.1
xen-doc-html-4.1.6_08-0.11.1
xen-doc-pdf-4.1.6_08-0.11.1
xen-libs-32bit-4.1.6_08-0.11.1
xen-tools-4.1.6_08-0.11.1

– SUSE Linux Enterprise Server 11 SP2 LTSS (i586):

xen-kmp-pae-4.1.6_08_3.0.101_0.7.29-0.11.1

References:

https://www.suse.com/security/cve/CVE-2015-3340.html
https://www.suse.com/security/cve/CVE-2015-3456.html
https://bugzilla.suse.com/910441
https://bugzilla.suse.com/927967
https://bugzilla.suse.com/929339
https://download.suse.com/patch/finder/?keywords=8be2bb05e7093a3facd3bc07a934547b


To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org

AutorMarko Stanec
Cert idNCERT-REF-2015-05-0028-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa phpMyAdmin

Otkriveni su sigurnosni nedostaci u programskom paketu phpMyAdmin za operacijski sustav Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izvođenje XSRF/CSRF napada...

Close