[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2014-0927 -- Oracle qemu-kvm, libcacard and qemu-guest-agent

ID: oval:org.secpod.oval:def:1500648Date: (C)2014-08-22   (M)2023-11-10
Class: PATCHFamily: unix




Two integer overflow flaws were found in the QEMU block driver for QCOW version 1 disk images. A user able to alter the QEMU disk image files loaded by a guest could use either of these flaws to corrupt QEMU process memory on the host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

Platform:
Oracle Linux 7
Product:
qemu-kvm
libcacard
qemu-guest-agent
Reference:
ELSA-2014-0927
CVE-2014-0182
CVE-2014-0222
CVE-2014-0223
CVE-2013-4148
CVE-2013-4149
CVE-2013-4150
CVE-2013-4151
CVE-2013-4527
CVE-2013-4529
CVE-2013-6399
CVE-2013-4542
CVE-2013-4541
CVE-2013-4535
CVE-2013-4536
CVE-2014-3461
CVE    15
CVE-2014-0222
CVE-2014-0223
CVE-2014-0182
CVE-2014-3461
...
CPE    4
cpe:/a:kvm_group:qemu-kvm
cpe:/a:spice-space:libcacard
cpe:/a:kvm_group:qemu_guest_agent
cpe:/o:oracle:linux:7
...

© SecPod Technologies