[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2017:0454 -- centos 5 kvm

ID: oval:org.secpod.oval:def:204453Date: (C)2017-03-09   (M)2023-12-07
Class: PATCHFamily: unix




KVM is a full virtualization solution for Linux on x86 hardware. Using KVM, one can run multiple virtual machines running unmodified Linux or Windows images. Each virtual machine has private virtualized hardware: a network card, disk, graphics adapter, etc. Security Fix: * Quick emulator built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host. * Quick emulator built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process. Red Hat would like to thank Wjjzhang and Li Qiang for reporting CVE-2017-2615. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

Platform:
CentOS 5
Product:
kvm
Reference:
CESA-2017:0454
CVE-2017-2615
CVE-2017-2620
CVE    2
CVE-2017-2620
CVE-2017-2615
CPE    2
cpe:/a:linux:kvm
cpe:/o:centos:centos:5

© SecPod Technologies