Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-2892

Опубликовано: 24 сент. 2019
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2019-2892: qemu-kvm security update (IMPORTANT)

[0.12.1.2-2.506.el6_10.5]

  • kvm-slirp-fix-big-little-endian-conversion-in-ident-prot.patch [bz#1669066]
  • kvm-slirp-ensure-there-is-enough-space-in-mbuf-to-null-t.patch [bz#1669066]
  • kvm-slirp-don-t-manipulate-so_rcv-in-tcp_emu.patch [bz#1669066]
  • kvm-qxl-check-release-info-object.patch [bz#1712728]
  • kvm-net-Use-iov-helper-functions.patch [bz#1636415]
  • kvm-net-increase-buffer-size-to-accommodate-Jumbo-frame-.patch [bz#1636415]
  • kvm-net-ignore-packet-size-greater-than-INT_MAX.patch [bz#1636415]
  • kvm-net-drop-too-large-packet-early.patch [bz#1636415]
  • kvm-PATCH-slirp-fix-buffer-overrun.patch [bz#1586251]
  • kvm-Fix-build-from-previous-commit.patch [bz#1586251]
  • kvm-slirp-remove-mbuf-m_hdr-m_dat-indirection.patch [bz#1586251]
  • kvm-slirp-Convert-mbufs-to-use-g_malloc-and-g_free.patch [bz#1586251]
  • kvm-slirp-correct-size-computation-while-concatenating-m.patch [bz#1586251]
  • kvm-pcnet-fix-possible-buffer-overflow.patch [bz#1636774]
  • Resolves: bz#1586251 (CVE-2018-11806 qemu-kvm: QEMU: slirp: heap buffer overflow while reassembling fragmented datagrams [rhel-6.10.z])
  • Resolves: bz#1636415 (CVE-2018-10839 qemu-kvm: Qemu: ne2000: integer overflow leads to buffer overflow issue [rhel-6])
  • Resolves: bz#1636774 (CVE-2018-17962 qemu-kvm: Qemu: pcnet: integer overflow leads to buffer overflow [rhel-6])
  • Resolves: bz#1669066 (CVE-2019-6778 qemu-kvm: QEMU: slirp: heap buffer overflow in tcp_emu() [rhel-6.10.z])
  • Resolves: bz#1712728 (CVE-2019-12155 qemu-kvm: QEMU: qxl: null pointer dereference while releasing spice resources [rhel-6])

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

qemu-guest-agent

0.12.1.2-2.506.el6_10.5

qemu-img

0.12.1.2-2.506.el6_10.5

qemu-kvm

0.12.1.2-2.506.el6_10.5

qemu-kvm-tools

0.12.1.2-2.506.el6_10.5

Oracle Linux i686

qemu-guest-agent

0.12.1.2-2.506.el6_10.5

Связанные уязвимости

oracle-oval
больше 6 лет назад

ELSA-2018-4262: qemu security update (IMPORTANT)

CVSS3: 6.5
ubuntu
больше 6 лет назад

Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.

CVSS3: 6.5
redhat
больше 6 лет назад

Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.

CVSS3: 6.5
nvd
больше 6 лет назад

Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.

CVSS3: 6.5
debian
больше 6 лет назад

Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is ...