Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0896-1

Опубликовано: 12 мая 2015
Источник: suse-cvrf

Описание

Security update for qemu

qemu / kvm was updated to fix a security issue and some bugs.

Security issue fixed:

  • CVE-2015-3456: Fixed a buffer overflow in the floppy drive emulation, which could be used to denial of service attacks or potential code execution against the host.

  • CVE-2015-1779: Fixed insufficient resource limiting in the VNC websockets decoder.

Bugs fixed:

  • qemu truncates vhd images in virt-rescue (bsc#886378)

  • Update kvm-supported.txt with the current rbd support status.

  • enable rbd build on x86_64 (qemu-block-rbd package) (FATE#318349)

Список пакетов

SUSE Linux Enterprise Desktop 12
qemu-2.0.2-46.1
qemu-block-curl-2.0.2-46.1
qemu-ipxe-1.0.0-46.1
qemu-kvm-2.0.2-46.1
qemu-seabios-1.7.4-46.1
qemu-sgabios-8-46.1
qemu-tools-2.0.2-46.1
qemu-vgabios-1.7.4-46.1
qemu-x86-2.0.2-46.1
SUSE Linux Enterprise Server 12
qemu-2.0.2-46.1
qemu-block-curl-2.0.2-46.1
qemu-block-rbd-2.0.2-46.1
qemu-guest-agent-2.0.2-46.1
qemu-ipxe-1.0.0-46.1
qemu-kvm-2.0.2-46.1
qemu-lang-2.0.2-46.1
qemu-ppc-2.0.2-46.1
qemu-s390-2.0.2-46.1
qemu-seabios-1.7.4-46.1
qemu-sgabios-8-46.1
qemu-tools-2.0.2-46.1
qemu-vgabios-1.7.4-46.1
qemu-x86-2.0.2-46.1
SUSE Linux Enterprise Server for SAP Applications 12
qemu-2.0.2-46.1
qemu-block-curl-2.0.2-46.1
qemu-block-rbd-2.0.2-46.1
qemu-guest-agent-2.0.2-46.1
qemu-ipxe-1.0.0-46.1
qemu-kvm-2.0.2-46.1
qemu-lang-2.0.2-46.1
qemu-ppc-2.0.2-46.1
qemu-s390-2.0.2-46.1
qemu-seabios-1.7.4-46.1
qemu-sgabios-8-46.1
qemu-tools-2.0.2-46.1
qemu-vgabios-1.7.4-46.1
qemu-x86-2.0.2-46.1

Описание

The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:qemu-2.0.2-46.1
SUSE Linux Enterprise Desktop 12:qemu-block-curl-2.0.2-46.1
SUSE Linux Enterprise Desktop 12:qemu-ipxe-1.0.0-46.1
SUSE Linux Enterprise Desktop 12:qemu-kvm-2.0.2-46.1

Ссылки

Описание

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.


Затронутые продукты
SUSE Linux Enterprise Desktop 12:qemu-2.0.2-46.1
SUSE Linux Enterprise Desktop 12:qemu-block-curl-2.0.2-46.1
SUSE Linux Enterprise Desktop 12:qemu-ipxe-1.0.0-46.1
SUSE Linux Enterprise Desktop 12:qemu-kvm-2.0.2-46.1

Ссылки
Уязвимость SUSE-SU-2015:0896-1