SUSE Security Update: Security update for Xen
______________________________________________________________________________

Announcement ID:    SUSE-SU-2012:1129-1
Rating:             important
References:         #777084 #777090 
Cross-References:   CVE-2012-3494 CVE-2012-3515
Affected Products:
                    SUSE Linux Enterprise Server 10 SP3 LTSS
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.

Description:


   XEN was updated to fix multiple bugs and security issues.

   The following security issues have been fixed:

   * CVE-2012-3494: xen: hypercall set_debugreg
   vulnerability (XSA-12)
   * CVE-2012-3515: xen: Qemu VT100 emulation
   vulnerability (XSA-17)

   Security Issue references:

   * CVE-2012-3494
   
   * CVE-2012-3515
   

Indications:

   Everyone using XEN should update.


Package List:

   - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 x86_64):

      xen-3.2.3_17040_28-0.6.13.5
      xen-devel-3.2.3_17040_28-0.6.13.5
      xen-doc-html-3.2.3_17040_28-0.6.13.5
      xen-doc-pdf-3.2.3_17040_28-0.6.13.5
      xen-doc-ps-3.2.3_17040_28-0.6.13.5
      xen-kmp-debug-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5
      xen-kmp-default-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5
      xen-kmp-kdump-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5
      xen-kmp-smp-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5
      xen-libs-3.2.3_17040_28-0.6.13.5
      xen-tools-3.2.3_17040_28-0.6.13.5
      xen-tools-domU-3.2.3_17040_28-0.6.13.5
      xen-tools-ioemu-3.2.3_17040_28-0.6.13.5

   - SUSE Linux Enterprise Server 10 SP3 LTSS (x86_64):

      xen-libs-32bit-3.2.3_17040_28-0.6.13.5

   - SUSE Linux Enterprise Server 10 SP3 LTSS (i586):

      xen-kmp-bigsmp-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5
      xen-kmp-kdumppae-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5
      xen-kmp-vmi-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5
      xen-kmp-vmipae-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5


References:

   https://www.suse.com/security/cve/CVE-2012-3494.html
   https://www.suse.com/security/cve/CVE-2012-3515.html
   https://bugzilla.novell.com/777084
   https://bugzilla.novell.com/777090
   https://login.microfocus.com/nidp/app/login

SuSE: 2012:1129-1: important: Xen

September 6, 2012
An update that fixes two vulnerabilities is now available

Summary

XEN was updated to fix multiple bugs and security issues. The following security issues have been fixed: * CVE-2012-3494: xen: hypercall set_debugreg vulnerability (XSA-12) * CVE-2012-3515: xen: Qemu VT100 emulation vulnerability (XSA-17) Security Issue references: * CVE-2012-3494 * CVE-2012-3515 Indications: Everyone using XEN should update. Package List: - SUSE Linux Enterprise Server 10 SP3 LTSS (i586 x86_64): xen-3.2.3_17040_28-0.6.13.5 xen-devel-3.2.3_17040_28-0.6.13.5 xen-doc-html-3.2.3_17040_28-0.6.13.5 xen-doc-pdf-3.2.3_17040_28-0.6.13.5 xen-doc-ps-3.2.3_17040_28-0.6.13.5 xen-kmp-debug-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5 xen-kmp-default-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5 xen-kmp-kdump-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5 xen-kmp-smp-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5 xen-libs-3.2.3_17040_28-0.6.13.5 xen-tools-3.2.3_17040_28-0.6.13.5 xen-tools-domU-3.2.3_17040_28-0.6.13.5 xen-tools-ioemu-3.2.3_17040_28-0.6.13.5 - SUSE Linux Enterprise Server 10 SP3 LTSS (x86_64): xen-libs-32bit-3.2.3_17040_28-0.6.13.5 - SUSE Linux Enterprise Server 10 SP3 LTSS (i586): xen-kmp-bigsmp-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5 xen-kmp-kdumppae-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5 xen-kmp-vmi-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5 xen-kmp-vmipae-3.2.3_17040_28_2.6.16.60_0.83.169-0.6.13.5

References

#777084 #777090

Cross- CVE-2012-3494 CVE-2012-3515

Affected Products:

SUSE Linux Enterprise Server 10 SP3 LTSS

https://www.suse.com/security/cve/CVE-2012-3494.html

https://www.suse.com/security/cve/CVE-2012-3515.html

https://bugzilla.novell.com/777084

https://bugzilla.novell.com/777090

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2012:1129-1
Rating: important

Related News