PT-2013-6343 · Linux+2 · Linux Kernel+3

Prasad Pandit

·

Published

1970-01-01

·

Updated

2017-08-29

·

CVE-2014-1445

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise kernel-pae-devel (affected versions not specified) SUSE Linux Enterprise kernel-xen-devel (affected versions not specified) SUSE Linux Enterprise gfs2-kmp-xen (affected versions not specified) Linux kernel versions prior to 3.11.7 SUSE Linux Enterprise kernel-ec2-devel (affected versions not specified)
Description The issue concerns multiple vulnerabilities in various packages of the SUSE Linux Enterprise operating system, including kernel-pae-devel, kernel-xen-devel, gfs2-kmp-xen, and kernel-ec2-devel. These vulnerabilities can be exploited remotely and may lead to a breach of confidentiality, integrity, and availability of protected information. Additionally, a specific vulnerability in the Linux kernel before version 3.11.7 allows local users to obtain sensitive information from kernel memory via an ioctl call to the wanxl ioctl function in drivers/net/wan/wanxl.c.
Recommendations For SUSE Linux Enterprise kernel-pae-devel, consider disabling the vulnerable components until a patch is available. For SUSE Linux Enterprise kernel-xen-devel, restrict access to the vulnerable modules to minimize the risk of exploitation. For SUSE Linux Enterprise gfs2-kmp-xen, avoid using the vulnerable functions until the issue is resolved. For Linux kernel versions prior to 3.11.7, update to version 3.11.7 or later to resolve the issue. For SUSE Linux Enterprise kernel-ec2-devel, consider disabling the vulnerable components until a patch is available. At the moment, there is no information about a newer version that contains a fix for the SUSE Linux Enterprise kernel-pae-devel, kernel-xen-devel, gfs2-kmp-xen, and kernel-ec2-devel vulnerabilities.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1053
ALT-PU-2014-1422
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
CVE-2014-1445
DSA-2906-1
OPENSUSE-SU-2014_0677-1
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2040-1
USN-2042-1
USN-2049-1
USN-2050-1
USN-2066-1
USN-2067-1
USN-2069-1
USN-2128-1
USN-2129-1

Affected Products

Alt Linux
Linux Kernel
Suse Linux Enterprise
Suse