SuSE: 2013:1022-1: important: kernel SLE11 SP2
Summary
The SUSE Linux Enterprise 11 Service Pack 2 kernel was updated to Linux kernel 3.0.80, fixing various bugs and security issues. Following security issues were fixed: CVE-2013-0160: Timing side channel on attacks were possible on /dev/ptmx that could allow local attackers to predict keypresses like e.g. passwords. This has been fixed again by updating accessed/modified time on the pty devices in resolution of 8 seconds, so that idle time detection can still work. CVE-2013-3222: The vcc_recvmsg function in net/atm/common.c in the Linux kernel did not initialize a certain length variable, which allowed local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call. CVE-2013-3223: The ax25_recvmsg function in net/ax25/af_ax25.c in the Linux kernel did not initialize a certain data structure, which allowed local users to obtain sensitive information from kernel stack memory via a ...
Read the Full AdvisoryReferences
#763968 #764209 #768052 #769685 #788590 #792584
#793139 #797042 #797175 #800907 #802153 #804154
#804609 #805804 #805945 #806431 #806980 #808647
#809122 #809155 #809748 #809895 #810580 #810624
#810722 #812281 #814719 #815356 #815444 #815745
#816443 #816451 #816586 #816668 #816708 #817010
#817339 #818053 #818327 #818371 #818514 #818516
#818798 #819295 #819519 #819655 #819789 #820434
#821560 #821930 #822431 #822722
Cross- CVE-2013-0160 CVE-2013-1979 CVE-2013-3076
CVE-2013-3222 CVE-2013-3223 CVE-2013-3224
CVE-2013-3225 CVE-2013-3227 CVE-2013-3228
CVE-2013-3229 CVE-2013-3231 CVE-2013-3232
CVE-2013-3234 CVE-2013-3235
Affected Products:
SLE 11 SERVER Unsupported Extras
https://www.suse.com/security/cve/CVE-2013-0160.html
http...
Read the Full Advisory