SuSE: 2014:0928-1: important: ppc64-diag
Summary
ppc64-diag has been updated to prevent the usage of predictable filenames
in /tmp in various scripts and daemons (CVE-2014-4038) Also the snapshot
tarball was previously generated world readable, which could have leaked
sensible information, which is only visible to root, to all users. It is
now readable for root only (CVE-2014-4039).
Security Issues:
* CVE-2014-4038
References
#882667
Cross- CVE-2014-4038 CVE-2014-4039
Affected Products:
SUSE Linux Enterprise Server 11 SP3
https://www.suse.com/security/cve/CVE-2014-4038.html
https://www.suse.com/security/cve/CVE-2014-4039.html
https://bugzilla.novell.com/882667
https://scc.suse.com:443/patches/