Security update for xen
xen was updated to fix two security issues. These security issues were fixed: - CVE-2015-3259: xl command line config handling stack overflow (bsc#935634, XSA-137). - CVE-2015-5154: Host code execution via IDE subsystem CD-ROM (bsc#938344). These non-security issues were fixed: - Restart of xencommons service did lead to loss of xenstore data (bsc#935256). - Kdump did not work in a XEN environment (bsc#925466).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
xen was updated to fix two security issues. These security issues were fixed: - CVE-2015-3259: xl command line config handling stack overflow (bsc#935634, XSA-137). - CVE-2015-5154: Host code execution via IDE subsystem CD-ROM (bsc#938344). These non-security issues were fixed: - Restart of xencommons service did lead to loss of xenstore data (bsc#935256). - Kdump did not work in a XEN environment (bsc#925466).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/925466
- https://bugzilla.suse.com/935256
- https://bugzilla.suse.com/935634
- https://bugzilla.suse.com/938344
- https://www.suse.com/security/cve/CVE-2015-3259
- https://www.suse.com/security/cve/CVE-2015-5154
- https://www.suse.com/support/update/announcement/2015/suse-su-20151302-1/