SUSE-SU-2019:14201-1
Vulnerability Summary
Timeline
Description
Security update for xen This update for xen fixes the following issues: - CVE-2019-15890: Fixed a use-after-free in SLiRP networking implementation of QEMU emulator which could have led to Denial of Service (bsc#1149813). - CVE-2019-12068: Fixed an issue in lsi which could lead to an infinite loop and denial of service (bsc#1146874). - CVE-2019-14378: Fixed a heap buffer overflow in SLiRp networking implementation of QEMU emulator which could have led to execution of arbitrary code with privileges of the QEMU process (bsc#1143797). - CVE-2019-12067: Fixed a null pointer dereference which could have led to denial of service (bsc#1145652). - CVE-2019-12155: Fixed a null pointer dereference in QXL VGA card emulator of QEMU which could have led to denial of service (bsc#1135905). - CVE-2018-20815: Fixed a heap buffer overflow while loading device tree blob (bsc#1130680). - CVE-2017-10806: Fixed a stack buffer overflow in debug logging (bsc#1047675).
Affected Systems
- suse•xen&distro=SUSE Linux Enterprise Point of Sale 11 SP3
< 4.2.5_21-45.33.1
References (25)
- https://www.suse.com/support/update/announcement/2019/suse-su-201914201-1/
- https://bugzilla.suse.com/1047675
- https://bugzilla.suse.com/1126140
- https://bugzilla.suse.com/1126141
- https://bugzilla.suse.com/1126192
- https://bugzilla.suse.com/1126195
- https://bugzilla.suse.com/1126196
- https://bugzilla.suse.com/1130680
- https://bugzilla.suse.com/1135905
- https://bugzilla.suse.com/1143797
- https://bugzilla.suse.com/1145652
- https://bugzilla.suse.com/1146874
- https://bugzilla.suse.com/1149813
- https://www.suse.com/security/cve/CVE-2017-10806
- https://www.suse.com/security/cve/CVE-2018-20815
- https://www.suse.com/security/cve/CVE-2019-12067
- https://www.suse.com/security/cve/CVE-2019-12068
- https://www.suse.com/security/cve/CVE-2019-12155
- https://www.suse.com/security/cve/CVE-2019-14378
- https://www.suse.com/security/cve/CVE-2019-15890
- https://www.suse.com/security/cve/CVE-2019-17340
- https://www.suse.com/security/cve/CVE-2019-17341
- https://www.suse.com/security/cve/CVE-2019-17342
- https://www.suse.com/security/cve/CVE-2019-17343
- https://www.suse.com/security/cve/CVE-2019-17344