Oval Definition:
oval:org.opensuse.security:def:83133
Revision Date
:
2020-02-06
Version
:
1
Title
:
Security update for xen (Important)
Description
:
This update for xen fixes the following issues:
- CVE-2020-7211: potential directory traversal using relative paths via tftp server on Windows host (bsc#1161181). - CVE-2019-19579: Device quarantine for alternate pci assignment methods (bsc#1157888). - CVE-2019-19581: find_next_bit() issues (bsc#1158003). - CVE-2019-19583: VMentry failure with debug exceptions and blocked states (bsc#1158004). - CVE-2019-19578: Linear pagetable use / entry miscounts (bsc#1158005). - CVE-2019-19580: Further issues with restartable PV type change operations (bsc#1158006). - CVE-2019-19577: dynamic height for the IOMMU pagetables (bsc#1158007). - CVE-2019-18420: VCPUOP_initialise DoS (bsc#1154448). - CVE-2019-18425: missing descriptor table limit checking in x86 PV emulation (bsc#1154456). - CVE-2019-18421: Issues with restartable PV type change operations (bsc#1154458). - CVE-2019-18424: passed through PCI devices may corrupt host memory after deassignment (bsc#1154461). - CVE-2018-12207: Machine Check Error Avoidance on Page Size Change (aka IFU issue) (bsc#1155945). - CVE-2019-11135: TSX Asynchronous Abort (TAA) issue (bsc#1152497).
Family
:
unix
Class
:
patch
Status
:
Reference(s)
:
1152497
1154448
1154456
1154458
1154461
1155945
1157888
1158003
1158004
1158005
1158006
1158007
1161181
CVE-2018-12207
CVE-2019-11135
CVE-2019-18420
CVE-2019-18421
CVE-2019-18424
CVE-2019-18425
CVE-2019-19577
CVE-2019-19578
CVE-2019-19579
CVE-2019-19580
CVE-2019-19581
CVE-2019-19583
CVE-2020-7211
Platform(s)
:
SUSE Linux Enterprise Server 12 SP2-ESPOS
Product(s)
:
Definition Synopsis
SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
AND
Package Information
xen-4.7.6_06-43.59.1 is installed
OR
xen-doc-html-4.7.6_06-43.59.1 is installed
OR
xen-libs-4.7.6_06-43.59.1 is installed
OR
xen-libs-32bit-4.7.6_06-43.59.1 is installed
OR
xen-tools-4.7.6_06-43.59.1 is installed
OR
xen-tools-domU-4.7.6_06-43.59.1 is installed
BACK