Dva nedostatka otkrivena u programskom paketu kvm napadači mogu iskoristiti za DoS (eng. Denial of Service) napad i izvršavanje zlonamjernog programskog koda.
Prvi nedostatak se očituje kao preljev međuspremnika zbog nepravilnog rukovanja zahtjevima u redu čekanja. Drugi nedostatak je otkriven u funkciji "virtio_queue_notify()", a očituje se u nepravilnom rukovanju memorijom.
Posljedica:
Napadači mogu iskoristiti oba nedostatka za izvođenje DoS napada i pokretanje proizvoljnog programskog koda.
Rješenje:
Preporuča se korištenje odgovarajućih programskih zakrpi.
SUSE Security Update: Security update for KVM
______________________________________________________________________________
Announcement ID: SUSE-SU-2011:0806-1
Rating: critical
References: #626654 #695766 #698237 #701161 #702823
Cross-References: CVE-2011-2212 CVE-2011-2512
Affected Products:
SUSE Linux Enterprise Server 11 SP1
SUSE Linux Enterprise Desktop 11 SP1
______________________________________________________________________________
An update that solves two vulnerabilities and has three
fixes is now available. It includes one version update.
Description:
A privileged guest user could cause a buffer overflow in
the virtio subsystem of the host, therefore crashing the
guest or potentially execute arbitrary code on the host
(CVE-2011-2212, CVE-2011-2512).
Security Issue references:
* CVE-2011-2212
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2212
>
* CVE-2011-2512
<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2512
>
Patch Instructions:
To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:
- SUSE Linux Enterprise Server 11 SP1:
zypper in -t patch slessp1-kvm-4814
- SUSE Linux Enterprise Desktop 11 SP1:
zypper in -t patch sledsp1-kvm-4814
To bring your system up-to-date, use "zypper patch".
Package List:
- SUSE Linux Enterprise Server 11 SP1 (i586 x86_64) [New Version: 0.12.5]:
kvm-0.12.5-1.16.1
- SUSE Linux Enterprise Desktop 11 SP1 (i586 x86_64) [New Version: 0.12.5]:
kvm-0.12.5-1.16.1
References:
http://support.novell.com/security/cve/CVE-2011-2212.html
http://support.novell.com/security/cve/CVE-2011-2512.html
https://bugzilla.novell.com/626654
https://bugzilla.novell.com/695766
https://bugzilla.novell.com/698237
https://bugzilla.novell.com/701161
https://bugzilla.novell.com/702823
http://download.novell.com/patch/finder/?keywords=f5cdea8ccfe78b8840fa5072b0211851
--
To unsubscribe, e-mail: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
For additional commands, e-mail: Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke