Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-4079

Опубликовано: 08 окт. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-4079: qemu-kvm security update (IMPORTANT)

[1.5.3-175.el7_9.1]

  • Fixing release number for z-stream

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

qemu-img

1.5.3-175.el7_9.1

qemu-kvm

1.5.3-175.el7_9.1

qemu-kvm-common

1.5.3-175.el7_9.1

qemu-kvm-tools

1.5.3-175.el7_9.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

CVSS3: 6.5
redhat
около 5 лет назад

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

CVSS3: 7.5
nvd
около 5 лет назад

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

CVSS3: 7.5
debian
около 5 лет назад

A use after free vulnerability in ip_reass() in ip_input.c of libslirp ...

CVSS3: 5
ubuntu
почти 5 лет назад

An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of service, or the potential execution of arbitrary code with the privileges of the QEMU process on the host.