SUSE SLES10 Security Update : Xen (SUSE-SU-2014:0411-1)

This script is Copyright (C) 2015 Tenable Network Security, Inc.


Synopsis :

The remote SUSE host is missing one or more security updates.

Description :

The SUSE Linux Enterprise Server 10 Service Pack 4 LTSS Xen hypervisor
and toolset have been updated to fix various security issues.

The following security issues have been addressed :

- XSA-82: CVE-2013-6885: The microcode on AMD 16h 00h
through 0Fh processors does not properly handle the
interaction between locked instructions and
write-combined memory types, which allows local users to
cause a denial of service (system hang) via a crafted
application, aka the errata 793 issue. (bnc#853049)

- XSA-76: CVE-2013-4554: Xen 3.0.3 through 4.1.x (possibly
4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly
4.3.1) does not properly prevent access to hypercalls,
which allows local guest users to gain privileges via a
crafted application running in ring 1 or 2. (bnc#849668)

- XSA-73: CVE-2013-4494: Xen before 4.1.x, 4.2.x, and
4.3.x does not take the page_alloc_lock and
grant_table.lock in the same order, which allows local
guest administrators with access to multiple vcpus to
cause a denial of service (host deadlock) via
unspecified vectors. (bnc#848657)

- XSA-67: CVE-2013-4368: The outs instruction emulation in
Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or
GS: segment override, uses an uninitialized variable as
a segment base, which allows local 64-bit PV guests to
obtain sensitive information (hypervisor stack content)
via unspecified vectors related to stale data in a
segment register. (bnc#842511)

- XSA-63: CVE-2013-4355: Xen 4.3.x and earlier does not
properly handle certain errors, which allows local HVM
guests to obtain hypervisor stack memory via a (1) port
or (2) memory mapped I/O write or (3) other unspecified
operations related to addresses without associated
memory. (bnc#840592)

- XSA-55: CVE-2013-2196: Multiple unspecified
vulnerabilities in the Elf parser (libelf) in Xen 4.2.x
and earlier allow local guest administrators with
certain permissions to have an unspecified impact via a
crafted kernel, related to 'other problems' that are not
CVE-2013-2194 or CVE-2013-2195. (bnc#823011)

- XSA-55: CVE-2013-2195: The Elf parser (libelf) in Xen
4.2.x and earlier allow local guest administrators with
certain permissions to have an unspecified impact via a
crafted kernel, related to 'pointer dereferences'
involving unexpected calculations. (bnc#823011)

- XSA-55: CVE-2013-2194: Multiple integer overflows in the
Elf parser (libelf) in Xen 4.2.x and earlier allow local
guest administrators with certain permissions to have an
unspecified impact via a crafted kernel. (bnc#823011)

- XSA-47: CVE-2013-1920: Xen 4.2.x, 4.1.x, and earlier,
when the hypervisor is running 'under memory pressure'
and the Xen Security Module (XSM) is enabled, uses the
wrong ordering of operations when extending the
per-domain event channel tracking table, which causes a
use-after-free and allows local guest kernels to inject
arbitrary events and gain privileges via unspecified
vectors. (bnc#813677)

- XSA-44: CVE-2013-1917: Xen 3.1 through 4.x, when running
64-bit hosts on Intel CPUs, does not clear the NT flag
when using an IRET after a SYSENTER instruction, which
allows PV guest users to cause a denial of service
(hypervisor crash) by triggering a #GP fault, which is
not properly handled by another IRET instruction.
(bnc#813673)

- XSA-25: CVE-2012-4544: The PV domain builder in Xen 4.2
and earlier does not validate the size of the kernel or
ramdisk (1) before or (2) after decompression, which
allows local guest administrators to cause a denial of
service (domain 0 memory consumption) via a crafted (a)
kernel or (b) ramdisk. (bnc#787163)

Note that Tenable Network Security has extracted the preceding
description block directly from the SUSE security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://www.nessus.org/u?19638f54
http://support.novell.com/security/cve/CVE-2012-4544.html
http://support.novell.com/security/cve/CVE-2013-1917.html
http://support.novell.com/security/cve/CVE-2013-1920.html
http://support.novell.com/security/cve/CVE-2013-2194.html
http://support.novell.com/security/cve/CVE-2013-2195.html
http://support.novell.com/security/cve/CVE-2013-2196.html
http://support.novell.com/security/cve/CVE-2013-4355.html
http://support.novell.com/security/cve/CVE-2013-4368.html
http://support.novell.com/security/cve/CVE-2013-4494.html
http://support.novell.com/security/cve/CVE-2013-4554.html
http://support.novell.com/security/cve/CVE-2013-6885.html
https://bugzilla.novell.com/787163
https://bugzilla.novell.com/813673
https://bugzilla.novell.com/813677
https://bugzilla.novell.com/823011
https://bugzilla.novell.com/840592
https://bugzilla.novell.com/842511
https://bugzilla.novell.com/848657
https://bugzilla.novell.com/849668
https://bugzilla.novell.com/853049
http://www.nessus.org/u?132b6f16

Solution :

Update the affected Xen packages

Risk factor :

Medium / CVSS Base Score : 6.9
(CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.0
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now