Vulnerability   
Search   
    Search 211766 CVE descriptions
and 97459 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.4.2015.1479.1
Category:SuSE Local Security Checks
Title:SUSE: Security Advisory (SUSE-SU-2015:1479-1)
Summary:The remote host is missing an update for the 'xen' package(s) announced via the SUSE-SU-2015:1479-1 advisory.
Description:Summary:
The remote host is missing an update for the 'xen' package(s) announced via the SUSE-SU-2015:1479-1 advisory.

Vulnerability Insight:
xen was updated to fix the following security issues:
* CVE-2015-5165: QEMU leak of uninitialized heap memory in rtl8139 device
model (bsc#939712, XSA-140)
* CVE-2015-5166: Use after free in QEMU/Xen block unplug protocol
(bsc#939709, XSA-139)
* CVE-2015-2751: Certain domctl operations could have be used to lock up
the host (bsc#922709, XSA-127)
* CVE-2015-3259: xl command line config handling stack overflow
(bsc#935634, XSA-137)
* CVE-2015-4164: DoS through iret hypercall handler (bsc#932996, XSA-136)
* CVE-2015-5154: Host code execution via IDE subsystem CD-ROM (bsc#938344)

Affected Software/OS:
'xen' package(s) on SUSE Linux Enterprise Software Development Kit 11-SP3, SUSE Linux Enterprise Server 11-SP3, SUSE Linux Enterprise Desktop 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP3

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-2751
BugTraq ID: 73443
http://www.securityfocus.com/bid/73443
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154574.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155198.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154579.html
https://security.gentoo.org/glsa/201504-04
http://www.securitytracker.com/id/1031997
SuSE Security Announcement: SUSE-SU-2015:0923 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-3259
BugTraq ID: 75573
http://www.securityfocus.com/bid/75573
Debian Security Information: DSA-3414 (Google Search)
http://www.debian.org/security/2015/dsa-3414
https://security.gentoo.org/glsa/201604-03
http://www.securitytracker.com/id/1032973
SuSE Security Announcement: SUSE-SU-2015:1299 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00041.html
SuSE Security Announcement: SUSE-SU-2015:1302 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00042.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-4164
BugTraq ID: 75149
http://www.securityfocus.com/bid/75149
Debian Security Information: DSA-3286 (Google Search)
http://www.debian.org/security/2015/dsa-3286
http://www.securitytracker.com/id/1032569
SuSE Security Announcement: SUSE-SU-2015:1042 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00004.html
SuSE Security Announcement: SUSE-SU-2015:1045 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00007.html
SuSE Security Announcement: SUSE-SU-2015:1156 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00029.html
SuSE Security Announcement: SUSE-SU-2015:1157 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00030.html
SuSE Security Announcement: SUSE-SU-2015:1206 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00014.html
SuSE Security Announcement: SUSE-SU-2015:1643 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-5154
BugTraq ID: 76048
http://www.securityfocus.com/bid/76048
Debian Security Information: DSA-3348 (Google Search)
http://www.debian.org/security/2015/dsa-3348
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163658.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163472.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163681.html
https://security.gentoo.org/glsa/201510-02
RedHat Security Advisories: RHSA-2015:1507
http://rhn.redhat.com/errata/RHSA-2015-1507.html
RedHat Security Advisories: RHSA-2015:1508
http://rhn.redhat.com/errata/RHSA-2015-1508.html
RedHat Security Advisories: RHSA-2015:1512
http://rhn.redhat.com/errata/RHSA-2015-1512.html
http://www.securitytracker.com/id/1033074
SuSE Security Announcement: SUSE-SU-2015:1409 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00017.html
SuSE Security Announcement: SUSE-SU-2015:1421 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.html
SuSE Security Announcement: SUSE-SU-2015:1426 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00020.html
SuSE Security Announcement: SUSE-SU-2015:1455 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00022.html
SuSE Security Announcement: SUSE-SU-2015:1782 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00019.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-5165
BugTraq ID: 76153
http://www.securityfocus.com/bid/76153
Debian Security Information: DSA-3349 (Google Search)
http://www.debian.org/security/2015/dsa-3349
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165373.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167820.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167792.html
RedHat Security Advisories: RHSA-2015:1674
http://rhn.redhat.com/errata/RHSA-2015-1674.html
RedHat Security Advisories: RHSA-2015:1683
http://rhn.redhat.com/errata/RHSA-2015-1683.html
RedHat Security Advisories: RHSA-2015:1739
http://rhn.redhat.com/errata/RHSA-2015-1739.html
RedHat Security Advisories: RHSA-2015:1740
http://rhn.redhat.com/errata/RHSA-2015-1740.html
RedHat Security Advisories: RHSA-2015:1793
http://rhn.redhat.com/errata/RHSA-2015-1793.html
RedHat Security Advisories: RHSA-2015:1833
http://rhn.redhat.com/errata/RHSA-2015-1833.html
http://www.securitytracker.com/id/1033176
Common Vulnerability Exposure (CVE) ID: CVE-2015-5166
BugTraq ID: 76152
http://www.securityfocus.com/bid/76152
http://www.securitytracker.com/id/1033175
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.