Описание
Security update for kvm and libvirt
This collective update for KVM and libvirt provides fixes for security and non-security issues.
kvm:
libvirt:
Security Issues:
Список пакетов
SUSE Linux Enterprise Desktop 11 SP3
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP3-TERADATA
SUSE Linux Enterprise Server for SAP Applications 11 SP3
SUSE Linux Enterprise Software Development Kit 11 SP3
Ссылки
- Link for SUSE-SU-2015:0357-1
- E-Mail link for SUSE-SU-2015:0357-1
- SUSE Security Ratings
- SUSE Bug 843074
- SUSE Bug 852397
- SUSE Bug 878350
- SUSE Bug 879665
- SUSE Bug 897654
- SUSE Bug 897783
- SUSE Bug 899144
- SUSE Bug 899484
- SUSE Bug 900084
- SUSE Bug 904176
- SUSE Bug 905097
- SUSE Bug 907805
- SUSE Bug 908381
- SUSE Bug 910145
- SUSE Bug 911742
- SUSE CVE CVE-2014-3633 page
- SUSE CVE CVE-2014-3640 page
Описание
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
Затронутые продукты
Ссылки
- CVE-2014-3633
- SUSE Bug 897783
Описание
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.
Затронутые продукты
Ссылки
- CVE-2014-3640
- SUSE Bug 897654
- SUSE Bug 965112
Описание
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
Затронутые продукты
Ссылки
- CVE-2014-3657
- SUSE Bug 897783
- SUSE Bug 899484
Описание
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.
Затронутые продукты
Ссылки
- CVE-2014-7823
- SUSE Bug 904176
Описание
The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.
Затронутые продукты
Ссылки
- CVE-2014-7840
- SUSE Bug 905097
Описание
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
Затронутые продукты
Ссылки
- CVE-2014-8106
- SUSE Bug 1023004
- SUSE Bug 1178658
- SUSE Bug 907805