Bug 736671 (CVE-2012-2456) - VUL-0: CVE-2012-2456: microcode_ctl: [SLE11 SP2 RC1] update microcode to 20111110
Summary: VUL-0: CVE-2012-2456: microcode_ctl: [SLE11 SP2 RC1] update microcode to 2011...
Status: RESOLVED FIXED
Alias: CVE-2012-2456
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: x86-64 SLES 11
: P2 - High : Major
Target Milestone: ---
Deadline: 2012-01-18
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp1:44913
Keywords:
Depends on:
Blocks:
 
Reported: 2011-12-14 04:41 UTC by Youquan Song
Modified: 2017-11-13 14:29 UTC (History)
8 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Youquan Song 2011-12-14 04:41:25 UTC
User-Agent:       Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2; MS-RTC LM 8)

Microcode 20111110 version is available on:
http://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&DwnldID=20728&keyword=%22microcode%22&lang=eng

Please update it at SLE11 SP2.

Reproducible: Always

Steps to Reproduce:
1.
2.
3.
Comment 3 Swamp Workflow Management 2012-01-11 12:33:03 UTC
The SWAMPID for this issue is 44899.
This issue was rated as important.
Please submit fixed packages until 2012-01-18.
Also create a patchinfo file using this link:
https://swamp.suse.de/webswamp/wf/44899
Comment 4 Thomas Renninger 2012-01-11 16:34:27 UTC
Patch submitted to: SUSE:SLE-11-SP1:Update:Test
Swamp info provided.
I wasn't 100% sure about the category, afaik in SP1 TXT is not supported and I set category to "recommended" not "security"!

-> According to Dirk this will show up in SP2 automatically
-> reassigning to Dirk for finalizing
Comment 5 Marc Ruehrschneck 2012-01-12 11:25:04 UTC
TXT is not supported in SP1, but in SP2. At least we have the toolchain in place.
Comment 6 Swamp Workflow Management 2012-01-13 20:47:04 UTC
Update released for: microcode_ctl
Products:
SLE-DESKTOP 11-SP1 (i386, x86_64)
SLE-SERVER 11-SP1 (i386, x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
SLES4VMWARE 11-SP1 (i386, x86_64)
Comment 7 Dirk Mueller 2012-02-20 08:35:54 UTC
Resolving as fixed.
Comment 9 Marcus Meissner 2012-05-08 06:45:16 UTC
CVE-2012-2456.
Comment 10 Marcus Meissner 2017-11-13 14:29:35 UTC
I had some feedback session with Mitre on this, and this was assigned duplicate.

CVE-2011-5174 is the ID to be used for the SINIT buffer overflows.