SUSE Security Update: Security update for Xen
______________________________________________________________________________

Announcement ID:    SUSE-SU-2012:1135-1
Rating:             important
References:         #762484 #777084 #777090 
Cross-References:   CVE-2012-2625 CVE-2012-3494 CVE-2012-3515
                   
Affected Products:
                    SUSE Linux Enterprise Server 10 SP4
                    SUSE Linux Enterprise Desktop 10 SP4
                    SLE SDK 10 SP4
______________________________________________________________________________

   An update that fixes three vulnerabilities is now available.

Description:


   XEN was updated to fix multiple bugs and security issues.

   The following security issues have been fixed:

   * CVE-2012-3494: xen: hypercall set_debugreg
   vulnerability (XSA-12)
   * CVE-2012-3515: xen: Qemu VT100 emulation
   vulnerability (XSA-17)
   * CVE-2012-2625: xen: pv bootloader doesn't check the
   size of the bzip2 or lzma compressed kernel, leading to
   denial of service

   Security Issue references:

   * CVE-2012-3494
   
   * CVE-2012-3515
   
   * CVE-2012-2625
   

Indications:

   Everyone using XEN should update.


Package List:

   - SUSE Linux Enterprise Server 10 SP4 (i586 x86_64):

      xen-3.2.3_17040_40-0.7.2
      xen-devel-3.2.3_17040_40-0.7.2
      xen-doc-html-3.2.3_17040_40-0.7.2
      xen-doc-pdf-3.2.3_17040_40-0.7.2
      xen-doc-ps-3.2.3_17040_40-0.7.2
      xen-kmp-debug-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-kmp-default-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-kmp-kdump-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-kmp-smp-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-libs-3.2.3_17040_40-0.7.2
      xen-tools-3.2.3_17040_40-0.7.2
      xen-tools-domU-3.2.3_17040_40-0.7.2
      xen-tools-ioemu-3.2.3_17040_40-0.7.2

   - SUSE Linux Enterprise Server 10 SP4 (x86_64):

      xen-libs-32bit-3.2.3_17040_40-0.7.2

   - SUSE Linux Enterprise Server 10 SP4 (i586):

      xen-kmp-bigsmp-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-kmp-kdumppae-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-kmp-vmi-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-kmp-vmipae-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2

   - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64):

      xen-3.2.3_17040_40-0.7.2
      xen-devel-3.2.3_17040_40-0.7.2
      xen-doc-html-3.2.3_17040_40-0.7.2
      xen-doc-pdf-3.2.3_17040_40-0.7.2
      xen-doc-ps-3.2.3_17040_40-0.7.2
      xen-kmp-default-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-kmp-smp-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-libs-3.2.3_17040_40-0.7.2
      xen-tools-3.2.3_17040_40-0.7.2
      xen-tools-domU-3.2.3_17040_40-0.7.2
      xen-tools-ioemu-3.2.3_17040_40-0.7.2

   - SUSE Linux Enterprise Desktop 10 SP4 (x86_64):

      xen-libs-32bit-3.2.3_17040_40-0.7.2

   - SUSE Linux Enterprise Desktop 10 SP4 (i586):

      xen-kmp-bigsmp-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2

   - SLE SDK 10 SP4 (i586 x86_64):

      xen-3.2.3_17040_40-0.7.2
      xen-devel-3.2.3_17040_40-0.7.2
      xen-kmp-debug-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-kmp-kdump-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2
      xen-libs-3.2.3_17040_40-0.7.2
      xen-tools-3.2.3_17040_40-0.7.2
      xen-tools-ioemu-3.2.3_17040_40-0.7.2

   - SLE SDK 10 SP4 (x86_64):

      xen-libs-32bit-3.2.3_17040_40-0.7.2


References:

   https://www.suse.com/security/cve/CVE-2012-2625.html
   https://www.suse.com/security/cve/CVE-2012-3494.html
   https://www.suse.com/security/cve/CVE-2012-3515.html
   https://bugzilla.novell.com/762484
   https://bugzilla.novell.com/777084
   https://bugzilla.novell.com/777090
   https://login.microfocus.com/nidp/app/login

SuSE: 2012:1135-1: important: Xen

September 7, 2012
An update that fixes three vulnerabilities is now available

Summary

XEN was updated to fix multiple bugs and security issues. The following security issues have been fixed: * CVE-2012-3494: xen: hypercall set_debugreg vulnerability (XSA-12) * CVE-2012-3515: xen: Qemu VT100 emulation vulnerability (XSA-17) * CVE-2012-2625: xen: pv bootloader doesn't check the size of the bzip2 or lzma compressed kernel, leading to denial of service Security Issue references: * CVE-2012-3494 * CVE-2012-3515 * CVE-2012-2625 Indications: Everyone using XEN should update. Package List: - SUSE Linux Enterprise Server 10 SP4 (i586 x86_64): xen-3.2.3_17040_40-0.7.2 xen-devel-3.2.3_17040_40-0.7.2 xen-doc-html-3.2.3_17040_40-0.7.2 xen-doc-pdf-3.2.3_17040_40-0.7.2 xen-doc-ps-3.2.3_17040_40-0.7.2 xen-kmp-debug-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-kmp-default-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-kmp-kdump-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-kmp-smp-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-libs-3.2.3_17040_40-0.7.2 xen-tools-3.2.3_17040_40-0.7.2 xen-tools-domU-3.2.3_17040_40-0.7.2 xen-tools-ioemu-3.2.3_17040_40-0.7.2 - SUSE Linux Enterprise Server 10 SP4 (x86_64): xen-libs-32bit-3.2.3_17040_40-0.7.2 - SUSE Linux Enterprise Server 10 SP4 (i586): xen-kmp-bigsmp-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-kmp-kdumppae-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-kmp-vmi-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-kmp-vmipae-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64): xen-3.2.3_17040_40-0.7.2 xen-devel-3.2.3_17040_40-0.7.2 xen-doc-html-3.2.3_17040_40-0.7.2 xen-doc-pdf-3.2.3_17040_40-0.7.2 xen-doc-ps-3.2.3_17040_40-0.7.2 xen-kmp-default-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-kmp-smp-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-libs-3.2.3_17040_40-0.7.2 xen-tools-3.2.3_17040_40-0.7.2 xen-tools-domU-3.2.3_17040_40-0.7.2 xen-tools-ioemu-3.2.3_17040_40-0.7.2 - SUSE Linux Enterprise Desktop 10 SP4 (x86_64): xen-libs-32bit-3.2.3_17040_40-0.7.2 - SUSE Linux Enterprise Desktop 10 SP4 (i586): xen-kmp-bigsmp-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 - SLE SDK 10 SP4 (i586 x86_64): xen-3.2.3_17040_40-0.7.2 xen-devel-3.2.3_17040_40-0.7.2 xen-kmp-debug-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-kmp-kdump-3.2.3_17040_40_2.6.16.60_0.97.32-0.7.2 xen-libs-3.2.3_17040_40-0.7.2 xen-tools-3.2.3_17040_40-0.7.2 xen-tools-ioemu-3.2.3_17040_40-0.7.2 - SLE SDK 10 SP4 (x86_64): xen-libs-32bit-3.2.3_17040_40-0.7.2

References

#762484 #777084 #777090

Cross- CVE-2012-2625 CVE-2012-3494 CVE-2012-3515

Affected Products:

SUSE Linux Enterprise Server 10 SP4

SUSE Linux Enterprise Desktop 10 SP4

SLE SDK 10 SP4

https://www.suse.com/security/cve/CVE-2012-2625.html

https://www.suse.com/security/cve/CVE-2012-3494.html

https://www.suse.com/security/cve/CVE-2012-3515.html

https://bugzilla.novell.com/762484

https://bugzilla.novell.com/777084

https://bugzilla.novell.com/777090

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2012:1135-1
Rating: important

Related News