Описание
Security update for KVM
This update fixes a file permission issue with qga (the QEMU Guest Agent) from the qemu/kvm package and includes several bug-fixes.
(bnc#818182) (CVE-2013-2007) (bnc#786813) (bnc#725008) (bnc#712137) (bnc#824340)
Security Issues:
Список пакетов
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP2-LTSS
SUSE Linux Enterprise Server for SAP Applications 11 SP2
Ссылки
- Link for SUSE-SU-2015:0943-1
- E-Mail link for SUSE-SU-2015:0943-1
- SUSE Security Ratings
- SUSE Bug 709405
- SUSE Bug 712137
- SUSE Bug 722643
- SUSE Bug 722958
- SUSE Bug 724813
- SUSE Bug 725008
- SUSE Bug 747339
- SUSE Bug 753313
- SUSE Bug 757031
- SUSE Bug 764526
- SUSE Bug 770153
- SUSE Bug 772586
- SUSE Bug 777084
- SUSE Bug 786813
- SUSE Bug 818182
- SUSE Bug 824340
- SUSE Bug 834196
Описание
The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.
Затронутые продукты
Ссылки
- CVE-2012-2652
- SUSE Bug 764526
Описание
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
Затронутые продукты
Ссылки
- CVE-2012-3515
- SUSE Bug 777084
Описание
The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.
Затронутые продукты
Ссылки
- CVE-2013-2007
- SUSE Bug 818181
- SUSE Bug 818182
- SUSE Bug 818183
Описание
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
Затронутые продукты
Ссылки
- CVE-2015-3456
- SUSE Bug 929339
- SUSE Bug 932770
- SUSE Bug 935900