Novell Home

CVE-2013-4368

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-4368 at MITRE

Description

The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.

NVD CVSS v2 Base Score: 1.9 (AV:L/AC:M/Au:N/C:P/I:N/A:N)

Novell/SUSE information

Novell Bugzilla entries: 840592, 842511

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Software Development Kit 11 SP2
  • xen-devel >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Server 11 SP2
  • xen-kmp-default >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-kmp-pae >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-kmp-trace >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-libs >= 4.1.6_02-0.5.1
  • xen-tools-domU >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Server 11 SP2
  • xen >= 4.1.6_02-0.5.1
  • xen-doc-html >= 4.1.6_02-0.5.1
  • xen-doc-pdf >= 4.1.6_02-0.5.1
  • xen-kmp-default >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-kmp-trace >= 4.1.6_02_3.0.93_0.5-0.5.1
  • xen-libs >= 4.1.6_02-0.5.1
  • xen-libs-32bit >= 4.1.6_02-0.5.1
  • xen-tools >= 4.1.6_02-0.5.1
  • xen-tools-domU >= 4.1.6_02-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Server 11 SP2 for VMware
  • xen-kmp-trace >= 4.1.6_02_3.0.93_0.5-0.5.1
Builds
SAT Patch Nr: 8478
SUSE Linux Enterprise Software Development Kit 11 SP3
  • xen-devel >= 4.2.3_02-0.7.1
Builds
SAT Patch Nr: 8479
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
  • xen-kmp-default >= 4.2.3_02_3.0.93_0.8-0.7.1
  • xen-kmp-pae >= 4.2.3_02_3.0.93_0.8-0.7.1
  • xen-libs >= 4.2.3_02-0.7.1
  • xen-tools-domU >= 4.2.3_02-0.7.1
Builds
SAT Patch Nr: 8479
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
  • xen >= 4.2.3_02-0.7.1
  • xen-doc-html >= 4.2.3_02-0.7.1
  • xen-doc-pdf >= 4.2.3_02-0.7.1
  • xen-kmp-default >= 4.2.3_02_3.0.93_0.8-0.7.1
  • xen-libs >= 4.2.3_02-0.7.1
  • xen-libs-32bit >= 4.2.3_02-0.7.1
  • xen-tools >= 4.2.3_02-0.7.1
  • xen-tools-domU >= 4.2.3_02-0.7.1
Builds
SAT Patch Nr: 8479
SUSE Linux Enterprise Server 10 SP4 LTSS for x86
  • xen >= 3.2.3_17040_46-0.7.1
  • xen-devel >= 3.2.3_17040_46-0.7.1
  • xen-doc-html >= 3.2.3_17040_46-0.7.1
  • xen-doc-pdf >= 3.2.3_17040_46-0.7.1
  • xen-doc-ps >= 3.2.3_17040_46-0.7.1
  • xen-kmp-bigsmp >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-debug >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-default >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-kdump >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-kdumppae >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-smp >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-vmi >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-vmipae >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-libs >= 3.2.3_17040_46-0.7.1
  • xen-tools >= 3.2.3_17040_46-0.7.1
  • xen-tools-domU >= 3.2.3_17040_46-0.7.1
  • xen-tools-ioemu >= 3.2.3_17040_46-0.7.1
Builds
ZYPP Patch Nr: 8791
SUSE Linux Enterprise Server 10 SP4 LTSS for AMD64 and Intel EM64T
  • xen >= 3.2.3_17040_46-0.7.1
  • xen-devel >= 3.2.3_17040_46-0.7.1
  • xen-doc-html >= 3.2.3_17040_46-0.7.1
  • xen-doc-pdf >= 3.2.3_17040_46-0.7.1
  • xen-doc-ps >= 3.2.3_17040_46-0.7.1
  • xen-kmp-debug >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-default >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-kdump >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-kmp-smp >= 3.2.3_17040_46_2.6.16.60_0.103.13-0.7.1
  • xen-libs >= 3.2.3_17040_46-0.7.1
  • xen-libs-32bit >= 3.2.3_17040_46-0.7.1
  • xen-tools >= 3.2.3_17040_46-0.7.1
  • xen-tools-domU >= 3.2.3_17040_46-0.7.1
  • xen-tools-ioemu >= 3.2.3_17040_46-0.7.1
Builds
ZYPP Patch Nr: 8791
SUSE Linux Enterprise Server 10 SP3 LTSS for x86
  • xen >= 3.2.3_17040_28-0.6.21.3
  • xen-devel >= 3.2.3_17040_28-0.6.21.3
  • xen-doc-html >= 3.2.3_17040_28-0.6.21.3
  • xen-doc-pdf >= 3.2.3_17040_28-0.6.21.3
  • xen-doc-ps >= 3.2.3_17040_28-0.6.21.3
  • xen-kmp-bigsmp >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-debug >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-default >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-kdump >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-kdumppae >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-smp >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-vmi >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-vmipae >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-libs >= 3.2.3_17040_28-0.6.21.3
  • xen-tools >= 3.2.3_17040_28-0.6.21.3
  • xen-tools-domU >= 3.2.3_17040_28-0.6.21.3
  • xen-tools-ioemu >= 3.2.3_17040_28-0.6.21.3
Builds
ZYPP Patch Nr: 8808
SUSE Linux Enterprise Server 10 SP3 LTSS for AMD64 and Intel EM64T
  • xen >= 3.2.3_17040_28-0.6.21.3
  • xen-devel >= 3.2.3_17040_28-0.6.21.3
  • xen-doc-html >= 3.2.3_17040_28-0.6.21.3
  • xen-doc-pdf >= 3.2.3_17040_28-0.6.21.3
  • xen-doc-ps >= 3.2.3_17040_28-0.6.21.3
  • xen-kmp-debug >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-default >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-kdump >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-kmp-smp >= 3.2.3_17040_28_2.6.16.60_0.113.9-0.6.21.3
  • xen-libs >= 3.2.3_17040_28-0.6.21.3
  • xen-libs-32bit >= 3.2.3_17040_28-0.6.21.3
  • xen-tools >= 3.2.3_17040_28-0.6.21.3
  • xen-tools-domU >= 3.2.3_17040_28-0.6.21.3
  • xen-tools-ioemu >= 3.2.3_17040_28-0.6.21.3
Builds
ZYPP Patch Nr: 8808
SUSE Linux Enterprise Server 11 SP1 LTSS
  • xen >= 4.0.3_21548_16-0.5.1
  • xen-doc-html >= 4.0.3_21548_16-0.5.1
  • xen-doc-pdf >= 4.0.3_21548_16-0.5.1
  • xen-kmp-default >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-pae >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-trace >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-libs >= 4.0.3_21548_16-0.5.1
  • xen-tools >= 4.0.3_21548_16-0.5.1
  • xen-tools-domU >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963
SUSE Linux Enterprise Server 11 SP1 LTSS
  • xen >= 4.0.3_21548_16-0.5.1
  • xen-doc-html >= 4.0.3_21548_16-0.5.1
  • xen-doc-pdf >= 4.0.3_21548_16-0.5.1
  • xen-kmp-default >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-kmp-trace >= 4.0.3_21548_16_2.6.32.59_0.9-0.5.1
  • xen-libs >= 4.0.3_21548_16-0.5.1
  • xen-tools >= 4.0.3_21548_16-0.5.1
  • xen-tools-domU >= 4.0.3_21548_16-0.5.1
Builds
SAT Patch Nr: 8963

List of products where fixes are in QA

SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Software Development Kit 11 SP3

© 2014 Novell