SuSE: 2014:1619-1: important: shim
Summary
shim has been updated to fix three security issues:
* OOB read access when parsing DHCPv6 packets (remote DoS)
(CVE-2014-3675).
* Heap overflow when parsing IPv6 addresses provided by tftp:// DHCPv6
boot option (RCE) (CVE-2014-3676).
* Memory corruption when processing user provided MOK lists
(CVE-2014-3677).
Security Issues:
* CVE-2014-3675
References
#813448 #863205 #866690 #875385 #889332 #889765
Cross- CVE-2014-3675 CVE-2014-3676 CVE-2014-3677
Affected Products:
SUSE Linux Enterprise Software Development Kit 11 SP3
SUSE Linux Enterprise Server 11 SP3 for VMware
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Desktop 11 SP3
https://www.suse.com/security/cve/CVE-2014-3675.html
https://www.suse.com/security/cve/CVE-2014-3676.html
https://www.suse.com/security/cve/CVE-2014-3677.html
https://bugzilla.suse.com/show_bug.cgi?id=813448
https://bugzilla.suse.com/show_bug.cgi?id=863205
https://bugzilla.suse.com/show_bug.cgi?id=866690
https://bugzilla.suse.com/show_bug.cgi?id=875385
https://bugzilla.suse.com/show_bug.cgi?id=889332
https://bugzilla.suse.com/show_bug.cgi?id=889765
https://scc.suse.com:443/patches/