SuSE: 2015:0896-1: important: qemu
Summary
qemu / kvm was updated to fix a security issue and some bugs. Security issue fixed: * CVE-2015-3456: Fixed a buffer overflow in the floppy drive emulation, which could be used to denial of service attacks or potential code execution against the host. * CVE-2015-1779: Fixed insufficient resource limiting in the VNC websockets decoder. Bugs fixed: - qemu truncates vhd images in virt-rescue (bsc#886378) - Update kvm-supported.txt with the current rbd support status. - enable rbd build on x86_64 (qemu-block-rbd package) (FATE#318349) Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12: zypper in -t patch SUSE-SLE-SERVER-12-2015-200=1 - SUSE Linux Enterprise Desktop 12: zypper in -t patch SUSE-SLE-DESKTOP-12-2015-200=1 To bring your system up-to-date, use "zypper patch". Package ...
Read the Full AdvisoryReferences
#886378 #924018 #929339
Cross- CVE-2015-1779 CVE-2015-3456
Affected Products:
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 12
https://www.suse.com/security/cve/CVE-2015-1779.html
https://www.suse.com/security/cve/CVE-2015-3456.html
https://bugzilla.suse.com/886378
https://bugzilla.suse.com/924018
https://bugzilla.suse.com/929339