SuSE 11.3 Security Update : Xen (SAT Patch Number 10560)

This script is Copyright (C) 2015 Tenable Network Security, Inc.


Synopsis :

The remote SuSE 11 host is missing one or more security updates.

Description :

The Virtualization service XEN was updated to fix various bugs and
security issues.

The following security issues have been fixed :

- XSA-126: Unmediated PCI command register access in qemu
could have lead to denial of service attacks against the
host, if PCI cards are passed through to guests.
(CVE-2015-2756)

- XSA-125: Long latency MMIO mapping operations were not
preemptible.

- XSA-123: Instructions with register operands ignored
eventual segment overrides encoded for them. Due to an
insufficiently conditional assignment such a bogus
segment override could have, however, corrupted a
pointer used subsequently to store the result of the
instruction. (CVE-2015-2151)

- XSA-122: The code handling certain sub-operations of the
HYPERVISOR_xen_version hypercall failed to fully
initialize all fields of structures subsequently copied
back to guest memory. Due to this hypervisor stack
contents were copied into the destination of the
operation, thus becoming visible to the guest.
(CVE-2015-2045)

- XSA-121: Emulation routines in the hypervisor dealing
with certain system devices checked whether the access
size by the guest is a supported one. When the access
size is unsupported these routines failed to set the
data to be returned to the guest for read accesses, so
that hypervisor stack contents were copied into the
destination of the operation, thus becoming visible to
the guest. (CVE-2015-2044)

Also fixed :

- Fully virtualized guest install from network source
failed with 'cannot find guest domain' in XEN.
(bsc#919341)

See also :

https://bugzilla.novell.com/show_bug.cgi?id=918995
https://bugzilla.novell.com/show_bug.cgi?id=918998
https://bugzilla.novell.com/show_bug.cgi?id=919341
https://bugzilla.novell.com/show_bug.cgi?id=919464
https://bugzilla.novell.com/show_bug.cgi?id=922705
https://bugzilla.novell.com/show_bug.cgi?id=922706
http://support.novell.com/security/cve/CVE-2015-2044.html
http://support.novell.com/security/cve/CVE-2015-2045.html
http://support.novell.com/security/cve/CVE-2015-2151.html
http://support.novell.com/security/cve/CVE-2015-2756.html

Solution :

Apply SAT patch number 10560.

Risk factor :

High / CVSS Base Score : 7.2
(CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)

Family: SuSE Local Security Checks

Nessus Plugin ID: 82990 ()

Bugtraq ID:

CVE ID: CVE-2015-2044
CVE-2015-2045
CVE-2015-2151
CVE-2015-2756

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now