SUSE-SU-2015:1479-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1479-1
SUSE-SU-2015:1479-1
Summary: Security update for xen
Details: xen was updated to fix the following security issues: * CVE-2015-5165: QEMU leak of uninitialized heap memory in rtl8139 device model (bsc#939712, XSA-140) * CVE-2015-5166: Use after free in QEMU/Xen block unplug protocol (bsc#939709, XSA-139) * CVE-2015-2751: Certain domctl operations could have be used to lock up the host (bsc#922709, XSA-127) * CVE-2015-3259: xl command line config handling stack overflow (bsc#935634, XSA-137) * CVE-2015-4164: DoS through iret hypercall handler (bsc#932996, XSA-136) * CVE-2015-5154: Host code execution via IDE subsystem CD-ROM (bsc#938344)
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151479-1/, https://bugzilla.suse.com/922709, https://bugzilla.suse.com/932996, https://bugzilla.suse.com/935634, https://bugzilla.suse.com/938344, https://bugzilla.suse.com/939709, https://bugzilla.suse.com/939712, https://www.suse.com/security/cve/CVE-2015-2751, https://www.suse.com/security/cve/CVE-2015-3259, https://www.suse.com/security/cve/CVE-2015-4164, https://www.suse.com/security/cve/CVE-2015-5154, https://www.suse.com/security/cve/CVE-2015-5165, https://www.suse.com/security/cve/CVE-2015-5166
Affected packages
Package
Name: xen
Purl: pkg:rpm/suse/xen&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
