Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2017-2445

Опубликовано: 09 авг. 2017
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2017-2445: qemu-kvm security update (MODERATE)

[1.5.3-141.el7_4.1]

  • kvm-qemu-nbd-Ignore-SIGPIPE.patch [bz#1468107]
  • Resolves: bz#1468107 (CVE-2017-10664 qemu-kvm: Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort [rhel-7.4.z])

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

qemu-img

1.5.3-141.el7_4.1

qemu-kvm

1.5.3-141.el7_4.1

qemu-kvm-common

1.5.3-141.el7_4.1

qemu-kvm-tools

1.5.3-141.el7_4.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.

CVSS3: 5.3
redhat
больше 8 лет назад

qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.

CVSS3: 7.5
nvd
больше 8 лет назад

qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.

CVSS3: 7.5
debian
больше 8 лет назад

qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which a ...

CVSS3: 7.5
github
больше 3 лет назад

qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.