SuSE: 2013:1182-2: important: Linux kernel
Summary
The SUSE Linux Enterprise 11 Service Pack 3 kernel has been updated to 3.0.82 and to fix various bugs and security issues. The following security issues have been fixed: * CVE-2013-1774: The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel allowed local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter. * CVE-2013-0160: Timing side channel on attacks were possible on /dev/ptmx that could allow local attackers to predict keypresses like e.g. passwords. This has been fixed again by updating accessed/modified time on the pty devices in resolution of 8 seconds, so that idle time detection can still work. * CVE-2013-3222: The vcc_recvmsg function in net/atm/common.c in the Linux kernel did not initialize a certain length variable, which allowed local users to o...
Read the Full AdvisoryReferences
#763968 #773837 #785901 #797090 #797727 #801427
#803320 #804482 #804609 #805804 #806976 #808015
#808136 #808837 #808855 #809130 #809895 #809975
#810722 #812281 #812332 #812526 #812974 #813604
#813922 #815356 #816451 #817035 #817377 #818047
#818371 #818465 #819018 #819195 #819523 #819610
#819655 #820172 #820434 #821052 #821070 #821235
#821799 #821859 #821930 #822066 #822077 #822080
#822164 #822340 #822431 #822722 #822825 #823082
#823223 #823342 #823386 #823597 #823795 #824159
#825037 #825591 #825657 #825696 #826186
Cross- CVE-2013-0160 CVE-2013-1774 CVE-2013-1979
CVE-2013-3076 CVE-2013-3222 CVE-2013-3223
CVE-2013-3224 CVE-2013-3225 CVE-2013-3227
CVE-2013-3228 CVE-2013-3229 CVE-2013-3231
CVE-2013-3232 C...
Read the Full Advisory