|
|
Subscribe / Log in / New account

qemu: three vulnerabilities

Package(s):qemu, qemu-kvm CVE #(s):CVE-2015-7504 CVE-2015-7512 CVE-2015-8345
Created:December 3, 2015 Updated:February 22, 2016
Description: From the Ubuntu advisory:

Qinghao Tang and Ling Liu discovered that QEMU incorrectly handled the pcnet driver when used in loopback mode. A malicious guest could use this issue to cause a denial of service, or possibly execute arbitrary code on the host as the user running the QEMU process. In the default installation, when QEMU is used with libvirt, attackers would be isolated by the libvirt AppArmor profile. (CVE-2015-7504)

Ling Liu and Jason Wang discovered that QEMU incorrectly handled the pcnet driver. A remote attacker could use this issue to cause a denial of service, or possibly execute arbitrary code on the host as the user running the QEMU process. In the default installation, when QEMU is used with libvirt, attackers would be isolated by the libvirt AppArmor profile. (CVE-2015-7512)

Qinghao Tang discovered that QEMU incorrectly handled the eepro100 driver. A malicious guest could use this issue to cause an infinite loop, leading to a denial of service. (CVE-2015-8345)

Alerts:
openSUSE openSUSE-SU-2016:2494-1 xen 2016-10-11
SUSE SUSE-SU-2016:1745-1 xen 2016-07-06
Mageia MGASA-2016-0023 qemu 2016-01-17
openSUSE openSUSE-SU-2016:0126-1 xen 2016-01-14
openSUSE openSUSE-SU-2016:0124-1 xen 2016-01-14
openSUSE openSUSE-SU-2016:0123-1 xen 2016-01-14
SUSE SUSE-SU-2016:0020-1 kvm 2016-01-05
SUSE SUSE-SU-2016:0010-1 kvm 2016-01-04
Scientific Linux SLSA-2015:2694-1 qemu-kvm 2015-12-22
Oracle ELSA-2015-2694 qemu-kvm 2015-12-22
CentOS CESA-2015:2694 qemu-kvm 2015-12-22
Red Hat RHSA-2015:2695-01 qemu-kvm-rhev 2015-12-22
Red Hat RHSA-2015:2694-01 qemu-kvm 2015-12-22
SUSE SUSE-SU-2016:1318-1 xen 2016-05-17
Oracle ELSA-2016-0997 qemu-kvm 2016-05-17
SUSE SUSE-SU-2016:1154-1 xen 2016-04-26
openSUSE openSUSE-SU-2016:0995-1 xen 2016-04-08
SUSE SUSE-SU-2016:0955-1 xen 2016-04-05
Gentoo 201604-03 xen 2016-04-05
openSUSE openSUSE-SU-2016:0914-1 xen 2016-03-30
SUSE SUSE-SU-2016:0873-1 xen 2016-03-24
SUSE SUSE-SU-2016:0658-1 Xen 2016-03-04
Mageia MGASA-2016-0098 xen 2016-03-07
openSUSE openSUSE-SU-2016:0536-1 qemu 2016-02-21
SUSE SUSE-SU-2016:0459-1 qemu 2016-02-15
Debian DSA-3470-1 qemu-kvm 2016-02-08
Debian DSA-3471-1 qemu 2016-02-08
Debian DSA-3469-1 qemu 2016-02-08
Fedora FEDORA-2015-08e4af5a20 xen 2015-12-20
Gentoo 201602-01 qemu 2016-02-04
Fedora FEDORA-2015-12a089920e xen 2015-12-17
Fedora FEDORA-2015-2773b85b49 qemu 2015-12-17
Ubuntu USN-2828-1 qemu, qemu-kvm 2015-12-03

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds