<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for xen</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2018:0609-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2018-03-05T16:46:43Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2018-03-05T16:46:43Z</InitialReleaseDate>
    <CurrentReleaseDate>2018-03-05T16:46:43Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for xen</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for xen fixes several issues.

These security issues were fixed:

- CVE-2017-5753, CVE-2017-5715, CVE-2017-5754: Prevent information leaks via
  side effects of speculative execution, aka 'Spectre' and 'Meltdown' attacks
  (bsc#1074562, bsc#1068032)
- CVE-2018-5683: The vga_draw_text function allowed local OS guest privileged
  users to cause a denial of service (out-of-bounds read and QEMU process crash)
  by leveraging improper memory address validation (bsc#1076116).
- CVE-2017-18030: The cirrus_invalidate_region function allowed local OS guest
  privileged users to cause a denial of service (out-of-bounds array access and
  QEMU process crash) via vectors related to negative pitch (bsc#1076180).
- CVE-2017-15595: x86 PV guest OS users were able to cause a DoS (unbounded
  recursion, stack consumption, and hypervisor crash) or possibly gain privileges
  via crafted page-table stacking (bsc#1061081)
- CVE-2017-17566: Prevent PV guest OS users to cause a denial of service (host
  OS crash) or gain host OS privileges in shadow mode by mapping a certain
  auxiliary page (bsc#1070158).
- CVE-2017-17563: Prevent guest OS users to cause a denial of service (host OS
  crash) or gain host OS privileges by leveraging an incorrect mask for
  reference-count overflow checking in shadow mode (bsc#1070159).
- CVE-2017-17564: Prevent guest OS users to cause a denial of service (host OS
  crash) or gain host OS privileges by leveraging incorrect error handling for
  reference counting in shadow mode (bsc#1070160).
- CVE-2017-17565: Prevent PV guest OS users to cause a denial of service (host
  OS crash) if shadow mode and log-dirty mode are in place, because of an
  incorrect assertion related to M2P (bsc#1070163).
- Added missing intermediate preemption checks for guest requesting removal of
  memory. This allowed malicious guest administrator to cause denial of service
  due to the high cost of this operation (bsc#1080635).
- Because of XEN not returning the proper error messages when transitioning
  grant tables from v2 to v1 a malicious guest was able to cause DoS or
  potentially allowed for privilege escalation as well as information leaks
  (bsc#1080662).

This non-security issue was fixed:

- bsc#1035442: Increased the value of LIBXL_DESTROY_TIMEOUT from 10 to 100
  seconds. If many domUs shutdown in parallel the backends couldn't keep up
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-OpenStack-Cloud-6-2018-415,SUSE-SLE-SAP-12-SP1-2018-415,SUSE-SLE-SERVER-12-SP1-2018-415</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      <Description>Link for SUSE-SU-2018:0609-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2018-March/003789.html</URL>
      <Description>E-Mail link for SUSE-SU-2018:0609-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1035442</URL>
      <Description>SUSE Bug 1035442</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1061081</URL>
      <Description>SUSE Bug 1061081</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1068032</URL>
      <Description>SUSE Bug 1068032</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1070158</URL>
      <Description>SUSE Bug 1070158</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1070159</URL>
      <Description>SUSE Bug 1070159</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1070160</URL>
      <Description>SUSE Bug 1070160</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1070163</URL>
      <Description>SUSE Bug 1070163</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1074562</URL>
      <Description>SUSE Bug 1074562</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1076116</URL>
      <Description>SUSE Bug 1076116</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1076180</URL>
      <Description>SUSE Bug 1076180</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1080635</URL>
      <Description>SUSE Bug 1080635</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1080662</URL>
      <Description>SUSE Bug 1080662</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-15595/</URL>
      <Description>SUSE CVE CVE-2017-15595 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-17563/</URL>
      <Description>SUSE CVE CVE-2017-17563 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-17564/</URL>
      <Description>SUSE CVE CVE-2017-17564 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-17565/</URL>
      <Description>SUSE CVE CVE-2017-17565 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-17566/</URL>
      <Description>SUSE CVE CVE-2017-17566 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-18030/</URL>
      <Description>SUSE CVE CVE-2017-18030 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-5715/</URL>
      <Description>SUSE CVE CVE-2017-5715 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-5753/</URL>
      <Description>SUSE CVE CVE-2017-5753 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-5754/</URL>
      <Description>SUSE CVE CVE-2017-5754 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5683/</URL>
      <Description>SUSE CVE CVE-2018-5683 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP1-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS" CPE="cpe:/o:suse:sles-ltss:12:sp1">SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1" CPE="cpe:/o:suse:sles_sap:12:sp1">SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 6">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 6">
        <FullProductName ProductID="SUSE OpenStack Cloud 6" CPE="cpe:/o:suse:suse-openstack-cloud:6">SUSE OpenStack Cloud 6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="xen-4.5.5_24-22.43.1">
      <FullProductName ProductID="xen-4.5.5_24-22.43.1">xen-4.5.5_24-22.43.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-doc-html-4.5.5_24-22.43.1">
      <FullProductName ProductID="xen-doc-html-4.5.5_24-22.43.1">xen-doc-html-4.5.5_24-22.43.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1">
      <FullProductName ProductID="xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1">xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-libs-4.5.5_24-22.43.1">
      <FullProductName ProductID="xen-libs-4.5.5_24-22.43.1">xen-libs-4.5.5_24-22.43.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-libs-32bit-4.5.5_24-22.43.1">
      <FullProductName ProductID="xen-libs-32bit-4.5.5_24-22.43.1">xen-libs-32bit-4.5.5_24-22.43.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-tools-4.5.5_24-22.43.1">
      <FullProductName ProductID="xen-tools-4.5.5_24-22.43.1">xen-tools-4.5.5_24-22.43.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="xen-tools-domU-4.5.5_24-22.43.1">
      <FullProductName ProductID="xen-tools-domU-4.5.5_24-22.43.1">xen-tools-domU-4.5.5_24-22.43.1</FullProductName>
    </Branch>
    <Relationship ProductReference="xen-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1">xen-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-doc-html-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1">xen-doc-html-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1">xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1">xen-libs-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-32bit-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1">xen-libs-32bit-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1">xen-tools-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-domU-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1">xen-tools-domU-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1">xen-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-doc-html-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1">xen-doc-html-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1">xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1">xen-libs-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-32bit-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1">xen-libs-32bit-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1">xen-tools-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-domU-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1">xen-tools-domU-4.5.5_24-22.43.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1">xen-4.5.5_24-22.43.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-doc-html-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1">xen-doc-html-4.5.5_24-22.43.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1">xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1">xen-libs-4.5.5_24-22.43.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-libs-32bit-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1">xen-libs-32bit-4.5.5_24-22.43.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1">xen-tools-4.5.5_24-22.43.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="xen-tools-domU-4.5.5_24-22.43.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1">xen-tools-domU-4.5.5_24-22.43.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and hypervisor crash) or possibly gain privileges via crafted page-table stacking.</Note>
    </Notes>
    <CVE>CVE-2017-15595</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.2</BaseScore>
        <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>7.2</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-15595.html</URL>
        <Description>CVE-2017-15595</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1061081</URL>
        <Description>SUSE Bug 1061081</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging an incorrect mask for reference-count overflow checking in shadow mode.</Note>
    </Notes>
    <CVE>CVE-2017-17563</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:A/AC:M/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-17563.html</URL>
        <Description>CVE-2017-17563</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1070159</URL>
        <Description>SUSE Bug 1070159</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by leveraging incorrect error handling for reference counting in shadow mode.</Note>
    </Notes>
    <CVE>CVE-2017-17564</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:A/AC:M/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-17564.html</URL>
        <Description>CVE-2017-17564</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1070160</URL>
        <Description>SUSE Bug 1070160</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) if shadow mode and log-dirty mode are in place, because of an incorrect assertion related to M2P.</Note>
    </Notes>
    <CVE>CVE-2017-17565</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.3</BaseScore>
        <Vector>AV:A/AC:M/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4.7</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-17565.html</URL>
        <Description>CVE-2017-17565</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1070163</URL>
        <Description>SUSE Bug 1070163</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) or gain host OS privileges in shadow mode by mapping a certain auxiliary page.</Note>
    </Notes>
    <CVE>CVE-2017-17566</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:A/AC:M/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>6.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-17566.html</URL>
        <Description>CVE-2017-17566</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1070158</URL>
        <Description>SUSE Bug 1070158</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to negative pitch.</Note>
    </Notes>
    <CVE>CVE-2017-18030</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-18030.html</URL>
        <Description>CVE-2017-18030</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1076179</URL>
        <Description>SUSE Bug 1076179</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1076180</URL>
        <Description>SUSE Bug 1076180</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.</Note>
    </Notes>
    <CVE>CVE-2017-5715</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.7</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:N/A:N</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>1.9</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-5715.html</URL>
        <Description>CVE-2017-5715</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1068032</URL>
        <Description>SUSE Bug 1068032</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074562</URL>
        <Description>SUSE Bug 1074562</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074578</URL>
        <Description>SUSE Bug 1074578</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074701</URL>
        <Description>SUSE Bug 1074701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074741</URL>
        <Description>SUSE Bug 1074741</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074919</URL>
        <Description>SUSE Bug 1074919</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075006</URL>
        <Description>SUSE Bug 1075006</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075007</URL>
        <Description>SUSE Bug 1075007</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075262</URL>
        <Description>SUSE Bug 1075262</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075419</URL>
        <Description>SUSE Bug 1075419</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1076115</URL>
        <Description>SUSE Bug 1076115</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1076372</URL>
        <Description>SUSE Bug 1076372</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1076606</URL>
        <Description>SUSE Bug 1076606</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1078353</URL>
        <Description>SUSE Bug 1078353</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1080039</URL>
        <Description>SUSE Bug 1080039</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1087887</URL>
        <Description>SUSE Bug 1087887</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1087939</URL>
        <Description>SUSE Bug 1087939</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1088147</URL>
        <Description>SUSE Bug 1088147</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1089055</URL>
        <Description>SUSE Bug 1089055</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1091815</URL>
        <Description>SUSE Bug 1091815</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1095735</URL>
        <Description>SUSE Bug 1095735</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1102517</URL>
        <Description>SUSE Bug 1102517</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1105108</URL>
        <Description>SUSE Bug 1105108</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1126516</URL>
        <Description>SUSE Bug 1126516</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1173489</URL>
        <Description>SUSE Bug 1173489</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1201457</URL>
        <Description>SUSE Bug 1201457</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1201877</URL>
        <Description>SUSE Bug 1201877</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1203236</URL>
        <Description>SUSE Bug 1203236</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.</Note>
    </Notes>
    <CVE>CVE-2017-5753</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:C/I:N/A:N</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4.7</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-5753.html</URL>
        <Description>CVE-2017-5753</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1068032</URL>
        <Description>SUSE Bug 1068032</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074562</URL>
        <Description>SUSE Bug 1074562</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074578</URL>
        <Description>SUSE Bug 1074578</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074701</URL>
        <Description>SUSE Bug 1074701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075006</URL>
        <Description>SUSE Bug 1075006</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075419</URL>
        <Description>SUSE Bug 1075419</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075748</URL>
        <Description>SUSE Bug 1075748</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1080039</URL>
        <Description>SUSE Bug 1080039</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1087084</URL>
        <Description>SUSE Bug 1087084</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1087939</URL>
        <Description>SUSE Bug 1087939</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1089055</URL>
        <Description>SUSE Bug 1089055</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1136865</URL>
        <Description>SUSE Bug 1136865</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1201877</URL>
        <Description>SUSE Bug 1201877</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209547</URL>
        <Description>SUSE Bug 1209547</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.</Note>
    </Notes>
    <CVE>CVE-2017-5754</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:C/I:N/A:N</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4.7</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-5754.html</URL>
        <Description>CVE-2017-5754</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1068032</URL>
        <Description>SUSE Bug 1068032</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074562</URL>
        <Description>SUSE Bug 1074562</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074578</URL>
        <Description>SUSE Bug 1074578</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074701</URL>
        <Description>SUSE Bug 1074701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075006</URL>
        <Description>SUSE Bug 1075006</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075008</URL>
        <Description>SUSE Bug 1075008</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1087939</URL>
        <Description>SUSE Bug 1087939</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1089055</URL>
        <Description>SUSE Bug 1089055</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1115045</URL>
        <Description>SUSE Bug 1115045</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1136865</URL>
        <Description>SUSE Bug 1136865</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1201877</URL>
        <Description>SUSE Bug 1201877</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.</Note>
    </Notes>
    <CVE>CVE-2018-5683</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-doc-html-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-kmp-default-4.5.5_24_k3.12.74_60.64.82-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-32bit-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-libs-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-4.5.5_24-22.43.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:xen-tools-domU-4.5.5_24-22.43.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180609-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5683.html</URL>
        <Description>CVE-2018-5683</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1076114</URL>
        <Description>SUSE Bug 1076114</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1076116</URL>
        <Description>SUSE Bug 1076116</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
