Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2014-3124: xen: XSA-92: HVMOP_set_mem_type allows invalid P2M entries to be created | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Alexander Bergmann <abergmann> |
Component: | Incidents | Assignee: | Charles Arnold <carnold> |
Status: | VERIFIED INVALID | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | abergmann, jbeulich, jochen.roeder |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
Whiteboard: | maint:running:59647:moderate | ||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Alexander Bergmann
2014-04-29 13:47:36 UTC
bugbot adjusting priority CVE-2014-3124 was assigned to this issue. Charles/Jan are we affected by this? And if yes, which code-streams? (In reply to comment #3) > Charles/Jan are we affected by this? And if yes, which code-streams? SLE11-SP2 (Xen 4.1 - LTSS only) SLE11-SP3 (Xen 4.2) SLE12 (Xen 4.4 - Patched in Beta 6) os12.3 (Xen 4.2) os13.1 (Xen 4.3) (In reply to comment #3) > Charles/Jan are we affected by this? And if yes, which code-streams? In fact it depends on what you mean by "affected": Yes, the problematic code is there. But no, we don't support any form of disaggregation right now. That basically means we can close this bug as INVALID? I would think so, yes. thx openSUSE-SU-2014:1281-1: An update that solves 10 vulnerabilities and has four fixes is now available. Category: security (important) Bug References: 798770,820873,842006,864801,865682,875668,878841,880751,882127,895798,895799,895802,896023,897657 CVE References: CVE-2013-4344,CVE-2013-4540,CVE-2014-3124,CVE-2014-3967,CVE-2014-3968,CVE-2014-4021,CVE-2014-7154,CVE-2014-7155,CVE-2014-7156,CVE-2014-7188 Sources used: openSUSE 13.1 (src): xen-4.3.2_02-27.1 SUSE-SU-2014:1710-1: An update that solves 13 vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 826717,867910,875668,880751,895798,895799,895802,897657,901317,903850,903967,903970,905465,905467,906439 CVE References: CVE-2013-3495,CVE-2014-2599,CVE-2014-3124,CVE-2014-4021,CVE-2014-7154,CVE-2014-7155,CVE-2014-7156,CVE-2014-7188,CVE-2014-8594,CVE-2014-8595,CVE-2014-8866,CVE-2014-8867,CVE-2014-9030 Sources used: SUSE Linux Enterprise Server 11 SP2 LTSS (src): xen-4.1.6_08-0.5.1 |