[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4137-1 libvirt -- libvirt

ID: oval:org.secpod.oval:def:603310Date: (C)2018-03-16   (M)2024-01-29
Class: PATCHFamily: unix




Several vulnerabilities were discovered in Libvirt, a virtualisation abstraction library: CVE-2018-1064 Denial Berrange discovered that the QEMU guest agent performed insufficient validationof incoming data, which allows a privileged user in the guest to exhaust resources on the virtualisation host, resulting in denial of service. CVE-2018-5748 Daniel Berrange and Peter Krempa that the QEMU monitor was suspectible to denial of service by memory exhaustion. This was already fixed in Debian stretch and only affects Debian jessie. CVE-2018-6764 Pedro Sampaio discovered that LXC containes detected the hostname insecurely. This only affects Debian stretch.

Platform:
Debian 8.x
Debian 9.x
Product:
libvirt0
libvirt
libnss-libvirt
Reference:
DSA-4137-1
CVE-2018-1064
CVE-2018-5748
CVE-2018-6764
CVE    3
CVE-2018-1064
CVE-2018-6764
CVE-2018-5748
CPE    8
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:8.x
cpe:/a:redhat:libvirt:-
cpe:/o:debian:debian_linux:9.x
...

© SecPod Technologies