[Forgot Password]
Login  Register Subscribe

25354

 
 

132811

 
 

146396

 
 

909

 
 

117043

 
 

156

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4213-1 qemu -- qemu

ID: oval:org.secpod.oval:def:53337Date: (C)2019-04-04   (M)2020-06-25
Class: PATCHFamily: unix




Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2017-15038 Tuomas Tynkkynen discovered an information leak in 9pfs. CVE-2017-15119 Eric Blake discovered that the NBD server insufficiently restricts large option requests, resulting in denial of service. CVE-2017-15124 Daniel Berrange discovered that the integrated VNC server insufficiently restricted memory allocation, which could result in denial of service. CVE-2017-15268 A memory leak in websockets support may result in denial of service. CVE-2017-15289 Guoxiang Niu discovered an OOB write in the emulated Cirrus graphics adaptor which could result in denial of service. CVE-2017-16845 Cyrille Chatras discovered an information leak in PS/2 mouse and keyboard emulation which could be exploited during instance migration. CVE-2017-17381 Dengzhan Heyuandong Bijunhua and Liweichao discovered that an implementation error in the virtio vring implementation could result in denial of service. CVE-2017-18043 Eric Blake discovered an integer overflow in an internally used macro which could result in denial of service. CVE-2018-5683 Jiang Xin and Lin ZheCheng discovered an OOB memory access in the emulated VGA adaptor which could result in denial of service. CVE-2018-7550 Cyrille Chatras discovered that an OOB memory write when using multiboot could result in the execution of arbitrary code. This update also backports a number of mitigations against the Spectre v2 vulnerability affecting modern CPUs . For additional information please refer to https://www.qemu.org/2018/01/04/spectre/

Platform:
Linux Mint 3
Product:
qemu
Reference:
DSA-4213-1
CVE-2017-5715
CVE-2017-15038
CVE-2017-15119
CVE-2017-15124
CVE-2017-15268
CVE-2017-15289
CVE-2017-16845
CVE-2017-17381
CVE-2017-18043
CVE-2018-5683
CVE-2018-7550
CVE    11
CVE-2017-18043
CVE-2017-15289
CVE-2018-5683
CVE-2018-7550
...
CPE    111
cpe:/a:qemu:qemu:0.12.5
cpe:/a:qemu:qemu:1.0.1
cpe:/a:qemu:qemu:0.12.2
cpe:/a:qemu:qemu:0.12.1
...

© SecPod Technologies