Professional OVAL Repository
[Eng]
[Rus]
[Sign-In]
OVAL
Search
Categories
RedCheck
About
OVAL Definitions
OVAL Items
FSTEC Data Bank Information Security Threats
NKCKI
EOL (End Of Life)
Linux Security Advisories
Mozilla Foundation Security Advisory
IBM
VMware
Cisco
Check Point Software Technologies
Apache
Solaris
FreeBSD
Development
GitHub Enterprise
Google Chrome Security Advisories
Oracle Security Advisories
Adobe Security Advisories
OpenSSL Security Advisories
Microsoft
CVE
CWE
CPE
Latest Updates
OS ROSA
ALT Linux
Astra Linux SE 1.5
Astra Linux SE 1.6
RED OS
DSA (Debian Security Advisory) Patсh Statistics
DSA (Debian Security Advisory) Patсh Feed
DSA (Debian Security Advisory) Vulnerability Feed
DLA (Debian Security Advisory) Patсh Statistics
DLA (Debian Security Advisory) Patсh Feed
DLA (Debian Security Advisory) Vulnerability Feed
ALT Linux (Security Bulletins) Patсh Statistics
ALT Linux (Security Bulletins) Patсh Feed
ALT Linux (Security Bulletins) Vulnerability Feed
RED OS (Security Bulletins) Patсh Statistics
RED OS (Security Bulletins) Patсh Feed
RED OS (Security Bulletins) Vulnerability Feed
USN (Ubuntu Security Notice) Patсh Statistics
USN (Ubuntu Security Notice) Patсh Feed
USN (Ubuntu Security Notice) Vulnerability Feed
RHSA (RedHat Security Advisory) Patсh Statistics
RHSA (RedHat Security Advisory) Patсh Feed
RHSA (RedHat Security Advisory) Vulnerability Feed
ELSA (Oracle Linux Security Advisory) Patсh Statistics
ELSA (Oracle Linux Security Advisory) Patсh Feed
ELSA (Oracle Linux Security Advisory) Vulnerability Feed
SUSE (SUSE Security Advisories) Patсh Statistics
SUSE (SUSE Security Advisories) Patсh Feed
SUSE (SUSE Security Advisories) Vulnerability Feed
openSUSE (openSUSE Security Advisories) Patсh Statistics
openSUSE (openSUSE Security Advisories) Patсh Feed
openSUSE (openSUSE Security Advisories) Vulnerability Feed
Amazon Linux AMI (Security Bulletins) Patсh Statistics
Amazon Linux AMI (Security Bulletins) Patсh Feed
Amazon Linux AMI (Security Bulletins) Vulnerability Feed
Mageia Linux (Security Bulletins) Patсh Statistics
Mageia Linux (Security Bulletins) Patсh Feed
Mageia Linux (Security Bulletins) Vulnerability Feed
OS ROSA SX COBALT 1.0
OS ROSA DX COBALT 1.0
ROSA 7.3 (Security Advisories) Patсh Statistics
ROSA 7.3 (Security Advisories) Patсh Feed
ROSA 7.3 (Security Advisories) Vulnerability Feed
ALT Linux SPT 6.0
ALT Linux SPT 7.0
ALT 8 SP
ALT 9
RED OS Murom 7.1
RED OS Murom 7.2
IBM DB2
VMware Vulnerabilities Advisory (VMSA)
VMware vCenter Patch Advisories
VMware ESXi Patch Advisories
VMware NSX Patches
VMware NSX Vulnerabilities
VMware Photon OS 1.0 Patches
VMware Photon OS 1.0 Vulnerabilities
VMware Photon OS 2.0 Patches
VMware Photon OS 2.0 Vulnerabilities
Cisco ASA
Cisco IOS/NX-OS Advisory
Cisco NX-OS Vulnerabilities
Check Point Gaia
Apache Tomcat Advisories
Apache Tomcat Server
Apache HTTP Server
Python
Node.js
RubyGems
Qt
Microsoft Security Bulletin
Microsoft Knowledge Base Article
Microsoft SharePoint
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2013
Microsoft SharePoint Server 2016
About OVALdb
User manual
Pricing
Contact us
OVAL Definitions
>
OVAL Definition Details
Id
oval:com.altx-soft.nix:def:92788
[Rus]
Version
10
Class
patch
ALTXid
267767
Language
English
Severity
Critical
Title
ELSA-2018-4289 -- qemu security update
Description
[15:3.0.0-1.el7]
- net: ignore packet size greater than INT_MAX (Jason Wang) [Orabug: 28763782] {CVE-2018-17963}
- pcnet: fix possible buffer overflow (Jason Wang) [Orabug: 28763774] {CVE-2018-17962}
- rtl8139: fix possible out of bound access (Jason Wang) [Orabug: 28763765] {CVE-2018-17958}
- ne2000: fix possible out of bound access in ne2000_receive (Jason Wang) [Orabug: 28763758] {CVE-2018-10839}
- seccomp: set the seccomp filter to all threads (Marc-Andre Lureau) [Orabug: 28763748] {CVE-2018-15746}
- virtio_net: Introduce VIRTIO_NET_F_STANDBY feature bit to virtio_net (Sridhar Samudrala) [Orabug: 28763724]
Family
unix
Platform
Oracle Linux 7
Product
qemu
Reference
VENDOR: ELSA-2018-4289
VENDOR: ELSA-2018-4289
Id:
ELSA-2018-4289
Reference:
http://linux.oracle.com/errata/ELSA-2018-4289.html
CVE: CVE-2017-5715
CVE: CVE-2017-5715
Id:
CVE-2017-5715
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5715
Comment
: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
203 (Information Exposure Through Discrepancy)
References:
https://www.synology.com/support/security/Synology_SA_18_01 (CONFIRM)
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ (CONFIRM)
https://support.lenovo.com/us/en/solutions/LEN-18282 (CONFIRM)
https://support.f5.com/csp/article/K91229003 (CONFIRM)
https://spectreattack.com/ (MISC)
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr (CONFIRM)
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html (MISC)
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 (CONFIRM)
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html (MISC)
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ (CONFIRM)
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ (CONFIRM)
https://access.redhat.com/security/vulnerabilities/speculativeexecution (CONFIRM)
http://xenbits.xen.org/xsa/advisory-254.html (CONFIRM)
1040071 (SECTRACK)
VU#584653 (CERT-VN)
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 (CONFIRM)
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html (CONFIRM)
43427 (EXPLOIT-DB)
20180104 CPU Side-Channel Information Disclosure Vulnerabilities (CISCO)
https://support.citrix.com/article/CTX231399 (CONFIRM)
https://security.netapp.com/advisory/ntap-20180104-0001/ (CONFIRM)
102376 (BID)
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html (MISC)
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 (CONFIRM)
openSUSE-SU-2018:0023 (SUSE)
openSUSE-SU-2018:0022 (SUSE)
SUSE-SU-2018:0020 (SUSE)
SUSE-SU-2018:0019 (SUSE)
openSUSE-SU-2018:0013 (SUSE)
SUSE-SU-2018:0012 (SUSE)
SUSE-SU-2018:0011 (SUSE)
SUSE-SU-2018:0010 (SUSE)
SUSE-SU-2018:0009 (SUSE)
SUSE-SU-2018:0008 (SUSE)
SUSE-SU-2018:0007 (SUSE)
SUSE-SU-2018:0006 (SUSE)
https://www.vmware.com/us/security/advisories/VMSA-2018-0004.html (CONFIRM)
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us (CONFIRM)
USN-3516-1 (UBUNTU)
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html (CONFIRM)
RHSA-2018:0292 (REDHAT)
DSA-4120 (DEBIAN)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt (CONFIRM)
FreeBSD-SA-18:03 (FREEBSD)
USN-3597-2 (UBUNTU)
USN-3597-1 (UBUNTU)
USN-3594-1 (UBUNTU)
USN-3582-2 (UBUNTU)
USN-3582-1 (UBUNTU)
USN-3581-2 (UBUNTU)
USN-3581-1 (UBUNTU)
USN-3580-1 (UBUNTU)
USN-3561-1 (UBUNTU)
USN-3560-1 (UBUNTU)
USN-3549-1 (UBUNTU)
USN-3531-1 (UBUNTU)
USN-3542-2 (UBUNTU)
https://www.vmware.com/security/advisories/VMSA-2018-0007.html (CONFIRM)
USN-3541-2 (UBUNTU)
USN-3540-2 (UBUNTU)
USN-3531-3 (UBUNTU)
USN-3620-2 (UBUNTU)
DSA-4188 (DEBIAN)
DSA-4187 (DEBIAN)
[debian-lts-announce] 20180502 [SECURITY] [DLA 1369-1] linux security update (MLIST)
https://cert.vde.com/en-us/advisories/vde-2018-003 (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2018-002 (CONFIRM)
VU#180049 (CERT-VN)
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability (CONFIRM)
DSA-4213 (DEBIAN)
USN-3690-1 (UBUNTU)
[debian-lts-announce] 20180715 [SECURITY] [DLA 1422-2] linux security update (MLIST)
[debian-lts-announce] 20180714 [SECURITY] [DLA 1422-1] linux security update (MLIST)
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html (CONFIRM)
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us (CONFIRM)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
[debian-lts-announce] 20180916 [SECURITY] [DLA 1506-1] intel-microcode security update (MLIST)
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html (CONFIRM)
USN-3777-3 (UBUNTU)
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 (CONFIRM)
GLSA-201810-06 (GENTOO)
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes (CONFIRM)
20190624 [SECURITY] [DSA 4469-1] libvirt security update (BUGTRAQ)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html (MISC)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
FreeBSD-SA-19:26 (FREEBSD)
20191112 FreeBSD Security Advisory FreeBSD-SA-19:26.mcu (BUGTRAQ)
http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html (MISC)
https://security.paloaltonetworks.com/CVE-2017-5715 (CONFIRM)
[debian-lts-announce] 20200320 [SECURITY] [DLA 2148-1] amd64-microcode security update (MLIST)
[debian-lts-announce] 20210816 [SECURITY] [DLA 2743-1] amd64-microcode security update (MLIST)
CVE: CVE-2017-5753
CVE: CVE-2017-5753
Id:
CVE-2017-5753
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5753
Comment
: Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
203 (Information Exposure Through Discrepancy)
References:
https://www.synology.com/support/security/Synology_SA_18_01 (CONFIRM)
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ (CONFIRM)
https://support.lenovo.com/us/en/solutions/LEN-18282 (CONFIRM)
https://support.f5.com/csp/article/K91229003 (CONFIRM)
https://spectreattack.com/ (MISC)
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html (MISC)
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 (CONFIRM)
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html (MISC)
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ (CONFIRM)
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ (CONFIRM)
https://access.redhat.com/security/vulnerabilities/speculativeexecution (CONFIRM)
http://xenbits.xen.org/xsa/advisory-254.html (CONFIRM)
1040071 (SECTRACK)
VU#584653 (CERT-VN)
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 (CONFIRM)
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html (CONFIRM)
43427 (EXPLOIT-DB)
20180104 CPU Side-Channel Information Disclosure Vulnerabilities (CISCO)
https://support.citrix.com/article/CTX231399 (CONFIRM)
https://security.netapp.com/advisory/ntap-20180104-0001/ (CONFIRM)
102371 (BID)
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html (MISC)
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 (CONFIRM)
openSUSE-SU-2018:0023 (SUSE)
openSUSE-SU-2018:0022 (SUSE)
SUSE-SU-2018:0012 (SUSE)
SUSE-SU-2018:0011 (SUSE)
SUSE-SU-2018:0010 (SUSE)
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us (CONFIRM)
USN-3516-1 (UBUNTU)
RHSA-2018:0292 (REDHAT)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt (CONFIRM)
USN-3597-2 (UBUNTU)
USN-3597-1 (UBUNTU)
USN-3580-1 (UBUNTU)
USN-3549-1 (UBUNTU)
USN-3542-1 (UBUNTU)
USN-3541-1 (UBUNTU)
USN-3540-1 (UBUNTU)
USN-3542-2 (UBUNTU)
USN-3541-2 (UBUNTU)
USN-3540-2 (UBUNTU)
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html (CONFIRM)
DSA-4188 (DEBIAN)
DSA-4187 (DEBIAN)
https://cert.vde.com/en-us/advisories/vde-2018-003 (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2018-002 (CONFIRM)
VU#180049 (CERT-VN)
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability (CONFIRM)
[debian-lts-announce] 20180715 [SECURITY] [DLA 1422-2] linux security update (MLIST)
[debian-lts-announce] 20180714 [SECURITY] [DLA 1422-1] linux security update (MLIST)
[debian-lts-announce] 20180718 [SECURITY] [DLA 1423-1] linux-4.9 new package (MLIST)
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us (CONFIRM)
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 (CONFIRM)
GLSA-201810-06 (GENTOO)
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf (CONFIRM)
[debian-lts-announce] 20190327 [SECURITY] [DLA 1731-1] linux security update (MLIST)
[debian-lts-announce] 20190401 [SECURITY] [DLA 1731-2] linux regression update (MLIST)
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html (MISC)
20190624 [SECURITY] [DSA 4469-1] libvirt security update (BUGTRAQ)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
https://cdrdv2.intel.com/v1/dl/getContent/685359 (CONFIRM)
CVE: CVE-2017-5754
CVE: CVE-2017-5754
Id:
CVE-2017-5754
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5754
Comment
: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
CVSSv2 Score:
4.7
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:C/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
200 (Information Exposure)
References:
https://www.synology.com/support/security/Synology_SA_18_01 (CONFIRM)
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/ (CONFIRM)
https://support.lenovo.com/us/en/solutions/LEN-18282 (CONFIRM)
https://support.f5.com/csp/article/K91229003 (CONFIRM)
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html (MISC)
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002 (CONFIRM)
https://meltdownattack.com/ (MISC)
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html (MISC)
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/ (CONFIRM)
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/ (CONFIRM)
https://access.redhat.com/security/vulnerabilities/speculativeexecution (CONFIRM)
http://xenbits.xen.org/xsa/advisory-254.html (CONFIRM)
1040071 (SECTRACK)
VU#584653 (CERT-VN)
http://nvidia.custhelp.com/app/answers/detail/a_id/4609 (CONFIRM)
DSA-4078 (DEBIAN)
20180104 CPU Side-Channel Information Disclosure Vulnerabilities (CISCO)
https://support.citrix.com/article/CTX231399 (CONFIRM)
https://security.netapp.com/advisory/ntap-20180104-0001/ (CONFIRM)
102378 (BID)
http://nvidia.custhelp.com/app/answers/detail/a_id/4614 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4613 (CONFIRM)
http://nvidia.custhelp.com/app/answers/detail/a_id/4611 (CONFIRM)
openSUSE-SU-2018:0023 (SUSE)
openSUSE-SU-2018:0022 (SUSE)
SUSE-SU-2018:0012 (SUSE)
SUSE-SU-2018:0011 (SUSE)
SUSE-SU-2018:0010 (SUSE)
DSA-4082 (DEBIAN)
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us (CONFIRM)
USN-3525-1 (UBUNTU)
USN-3524-2 (UBUNTU)
USN-3523-2 (UBUNTU)
USN-3522-2 (UBUNTU)
USN-3516-1 (UBUNTU)
[debian-lts-announce] 20180107 [SECURITY] [DLA 1232-1] linux security update (MLIST)
RHSA-2018:0292 (REDHAT)
DSA-4120 (DEBIAN)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt (CONFIRM)
FreeBSD-SA-18:03 (FREEBSD)
USN-3597-2 (UBUNTU)
USN-3597-1 (UBUNTU)
USN-3583-1 (UBUNTU)
USN-3523-1 (UBUNTU)
USN-3522-4 (UBUNTU)
USN-3522-3 (UBUNTU)
USN-3541-2 (UBUNTU)
USN-3540-2 (UBUNTU)
https://source.android.com/security/bulletin/2018-04-01 (CONFIRM)
https://support.citrix.com/article/CTX234679 (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2018-003 (CONFIRM)
https://cert.vde.com/en-us/advisories/vde-2018-002 (CONFIRM)
VU#180049 (CERT-VN)
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability (CONFIRM)
https://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletin (CONFIRM)
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03871en_us (CONFIRM)
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0001 (CONFIRM)
GLSA-201810-06 (GENTOO)
https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes (CONFIRM)
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 (CONFIRM)
106128 (BID)
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html (MISC)
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2019-003.txt (CONFIRM)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
N/A (N/A)
https://cdrdv2.intel.com/v1/dl/getContent/685358 (CONFIRM)
CVE: CVE-2018-5683
CVE: CVE-2018-5683
Id:
CVE-2018-5683
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5683
Comment
: The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
125 (Out-of-bounds Read)
References:
[Qemu-devel] 20180112 Re: [Qemu-devel] [PATCH v3] vga: check the validation of memory addr when draw text (MLIST)
102518 (BID)
[oss-security] 20180115 CVE-2018-5683 Qemu: Out-of-bounds read in vga_draw_text routine (MLIST)
USN-3575-1 (UBUNTU)
RHSA-2018:1104 (REDHAT)
RHSA-2018:0816 (REDHAT)
DSA-4213 (DEBIAN)
RHSA-2018:2162 (REDHAT)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-13672
CVE: CVE-2017-13672
Id:
CVE-2017-13672
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13672
Comment
: QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
125 (Out-of-bounds Read)
References:
[qemu-devel] 20170824 [PATCH] vga: stop passing pointers to vga_draw_line* functions (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1486560 (CONFIRM)
[oss-security] 20170830 CVE-2017-13672 Qemu: vga: OOB read access during display update (MLIST)
100540 (BID)
DSA-3991 (DEBIAN)
USN-3575-1 (UBUNTU)
RHSA-2018:1104 (REDHAT)
RHSA-2018:0816 (REDHAT)
RHSA-2018:1113 (REDHAT)
RHSA-2018:2162 (REDHAT)
openSUSE-SU-2019:1074 (SUSE)
CVE: CVE-2017-13711
CVE: CVE-2017-13711
Id:
CVE-2017-13711
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13711
Comment
: Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
416 (Use After Free)
References:
[qemu-devel] 20170826 [PATCH] slirp: fix clearing ifq_so from pending packets (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1486400 (CONFIRM)
[oss-security] 20170829 CVE-2017-13711 Qemu: Slirp: use-after-free when sending response (MLIST)
100534 (BID)
DSA-3991 (DEBIAN)
RHSA-2018:1104 (REDHAT)
RHSA-2018:0816 (REDHAT)
RHSA-2018:1113 (REDHAT)
CVE: CVE-2017-15124
CVE: CVE-2017-15124
Id:
CVE-2017-15124
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15124
Comment
: VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
770 (Allocation of Resources Without Limits or Throttling)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=1525195 (CONFIRM)
USN-3575-1 (UBUNTU)
RHSA-2018:1104 (REDHAT)
RHSA-2018:0816 (REDHAT)
RHSA-2018:1113 (REDHAT)
102295 (BID)
DSA-4213 (DEBIAN)
RHSA-2018:3062 (REDHAT)
CVE: CVE-2017-15268
CVE: CVE-2017-15268
Id:
CVE-2017-15268
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15268
Comment
: Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[qemu-devel] 20171010 [PATCH v1 1/7] io: monitor encoutput buffer size from websocket GSource (MLIST)
https://bugs.launchpad.net/qemu/+bug/1718964 (CONFIRM)
101277 (BID)
USN-3575-1 (UBUNTU)
RHSA-2018:1104 (REDHAT)
RHSA-2018:0816 (REDHAT)
DSA-4213 (DEBIAN)
CVE: CVE-2018-7858
CVE: CVE-2018-7858
Id:
CVE-2018-7858
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7858
Comment
: Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
125 (Out-of-bounds Read)
References:
[qemu-devel] 20180308 [PATCH] vga: fix region calculation (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1553402 (CONFIRM)
[oss-security] 20180309 CVE-2018-7858 Qemu: cirrus: OOB access when updating vga display (MLIST)
103350 (BID)
RHSA-2018:1369 (REDHAT)
RHSA-2018:1416 (REDHAT)
USN-3649-1 (UBUNTU)
RHSA-2018:2162 (REDHAT)
openSUSE-SU-2019:1074 (SUSE)
CVE: CVE-2018-3639
CVE: CVE-2018-3639
Id:
CVE-2018-3639
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3639
Comment
: Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE:
203 (Information Exposure Through Discrepancy)
References:
TA18-141A (CERT)
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.html (CONFIRM)
https://www.synology.com/support/security/Synology_SA_18_23 (CONFIRM)
VU#180049 (CERT-VN)
USN-3655-2 (UBUNTU)
USN-3654-2 (UBUNTU)
USN-3654-1 (UBUNTU)
USN-3653-2 (UBUNTU)
USN-3653-1 (UBUNTU)
USN-3652-1 (UBUNTU)
USN-3651-1 (UBUNTU)
20180522 CPU Side-Channel Information Disclosure Vulnerabilities: May 2018 (CISCO)
https://support.citrix.com/article/CTX235225 (CONFIRM)
https://security.netapp.com/advisory/ntap-20180521-0001/ (CONFIRM)
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180012 (CONFIRM)
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability (CONFIRM)
https://bugs.chromium.org/p/project-zero/issues/detail?id=1528 (MISC)
RHSA-2018:1660 (REDHAT)
RHSA-2018:1655 (REDHAT)
RHSA-2018:1647 (REDHAT)
RHSA-2018:1630 (REDHAT)
http://xenbits.xen.org/xsa/advisory-263.html (CONFIRM)
1040949 (SECTRACK)
http://support.lenovo.com/us/en/solutions/LEN-22133 (CONFIRM)
RHSA-2018:1690 (REDHAT)
RHSA-2018:1689 (REDHAT)
RHSA-2018:1688 (REDHAT)
RHSA-2018:1686 (REDHAT)
RHSA-2018:1676 (REDHAT)
RHSA-2018:1675 (REDHAT)
RHSA-2018:1674 (REDHAT)
RHSA-2018:1669 (REDHAT)
RHSA-2018:1668 (REDHAT)
RHSA-2018:1667 (REDHAT)
RHSA-2018:1666 (REDHAT)
RHSA-2018:1665 (REDHAT)
RHSA-2018:1664 (REDHAT)
RHSA-2018:1663 (REDHAT)
RHSA-2018:1662 (REDHAT)
RHSA-2018:1661 (REDHAT)
RHSA-2018:1659 (REDHAT)
RHSA-2018:1658 (REDHAT)
RHSA-2018:1657 (REDHAT)
RHSA-2018:1656 (REDHAT)
RHSA-2018:1654 (REDHAT)
RHSA-2018:1653 (REDHAT)
RHSA-2018:1652 (REDHAT)
RHSA-2018:1651 (REDHAT)
RHSA-2018:1650 (REDHAT)
RHSA-2018:1649 (REDHAT)
RHSA-2018:1648 (REDHAT)
RHSA-2018:1646 (REDHAT)
RHSA-2018:1645 (REDHAT)
RHSA-2018:1644 (REDHAT)
RHSA-2018:1643 (REDHAT)
RHSA-2018:1642 (REDHAT)
RHSA-2018:1636 (REDHAT)
RHSA-2018:1635 (REDHAT)
RHSA-2018:1633 (REDHAT)
RHSA-2018:1632 (REDHAT)
RHSA-2018:1629 (REDHAT)
104232 (BID)
44695 (EXPLOIT-DB)
RHSA-2018:1711 (REDHAT)
RHSA-2018:1710 (REDHAT)
RHSA-2018:1696 (REDHAT)
DSA-4210 (DEBIAN)
USN-3655-1 (UBUNTU)
RHSA-2018:1738 (REDHAT)
RHSA-2018:1737 (REDHAT)
RHSA-2018:1641 (REDHAT)
RHSA-2018:1640 (REDHAT)
RHSA-2018:1639 (REDHAT)
RHSA-2018:1638 (REDHAT)
RHSA-2018:1637 (REDHAT)
http://www.fujitsu.com/global/support/products/software/security/products-f/cve-2018-3639e.html (CONFIRM)
USN-3680-1 (UBUNTU)
USN-3679-1 (UBUNTU)
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03850en_us (CONFIRM)
RHSA-2018:1826 (REDHAT)
RHSA-2018:1854 (REDHAT)
RHSA-2018:2006 (REDHAT)
RHSA-2018:2003 (REDHAT)
RHSA-2018:2001 (REDHAT)
RHSA-2018:1997 (REDHAT)
RHSA-2018:1967 (REDHAT)
RHSA-2018:1965 (REDHAT)
RHSA-2018:2060 (REDHAT)
RHSA-2018:2164 (REDHAT)
RHSA-2018:2162 (REDHAT)
RHSA-2018:2161 (REDHAT)
RHSA-2018:2172 (REDHAT)
RHSA-2018:2171 (REDHAT)
RHSA-2018:2216 (REDHAT)
[debian-lts-announce] 20180718 [SECURITY] [DLA 1423-1] linux-4.9 new package (MLIST)
RHSA-2018:2228 (REDHAT)
RHSA-2018:2250 (REDHAT)
RHSA-2018:2246 (REDHAT)
RHSA-2018:2258 (REDHAT)
[debian-lts-announce] 20180727 [SECURITY] [DLA 1446-1] intel-microcode security update (MLIST)
RHSA-2018:2289 (REDHAT)
RHSA-2018:2328 (REDHAT)
RHSA-2018:2309 (REDHAT)
RHSA-2018:2364 (REDHAT)
RHSA-2018:2363 (REDHAT)
RHSA-2018:2396 (REDHAT)
RHSA-2018:2394 (REDHAT)
RHSA-2018:2387 (REDHAT)
DSA-4273 (DEBIAN)
USN-3756-1 (UBUNTU)
https://cert-portal.siemens.com/productcert/pdf/ssa-268644.pdf (CONFIRM)
[debian-lts-announce] 20180916 [SECURITY] [DLA 1506-1] intel-microcode security update (MLIST)
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0004 (CONFIRM)
USN-3777-3 (UBUNTU)
https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-18-0006 (CONFIRM)
RHSA-2018:3425 (REDHAT)
RHSA-2018:3424 (REDHAT)
RHSA-2018:3423 (REDHAT)
RHSA-2018:3407 (REDHAT)
RHSA-2018:3402 (REDHAT)
RHSA-2018:3401 (REDHAT)
RHSA-2018:3400 (REDHAT)
RHSA-2018:3399 (REDHAT)
RHSA-2018:3398 (REDHAT)
RHSA-2018:3397 (REDHAT)
RHSA-2018:3396 (REDHAT)
RHSA-2018:2948 (REDHAT)
1042004 (SECTRACK)
https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 (CONFIRM)
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html (CONFIRM)
RHSA-2019:0148 (REDHAT)
https://cert-portal.siemens.com/productcert/pdf/ssa-505225.pdf (CONFIRM)
[debian-lts-announce] 20190315 [SECURITY] [DLA 1715-1] linux-4.9 security update (MLIST)
[debian-lts-announce] 20190327 [SECURITY] [DLA 1731-1] linux security update (MLIST)
[debian-lts-announce] 20190401 [SECURITY] [DLA 1731-2] linux regression update (MLIST)
https://nvidia.custhelp.com/app/answers/detail/a_id/4787 (CONFIRM)
https://support.oracle.com/knowledge/Sun%20Microsystems/2481872_1.html (CONFIRM)
RHSA-2019:1046 (REDHAT)
openSUSE-SU-2019:1439 (SUSE)
openSUSE-SU-2019:1438 (SUSE)
20190624 [SECURITY] [DSA 4469-1] libvirt security update (BUGTRAQ)
https://cert-portal.siemens.com/productcert/pdf/ssa-608355.pdf (CONFIRM)
[oss-security] 20200610 kernel: Multiple SSBD related flaws CVE-2020-10766 , CVE-2020-10767, CVE-2020-10768 (MLIST)
[oss-security] 20200610 Re: kernel: Multiple SSBD related flaws CVE-2020-10766 , CVE-2020-10767, CVE-2020-10768 (MLIST)
[oss-security] 20200610 Re: kernel: Multiple SSBD related flaws CVE-2020-10766 , CVE-2020-10767, CVE-2020-10768 (MLIST)
https://www.oracle.com/security-alerts/cpujul2020.html (MISC)
openSUSE-SU-2020:1325 (SUSE)
CVE: CVE-2017-14167
CVE: CVE-2017-14167
Id:
CVE-2017-14167
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14167
Comment
: Integer overflow in the load_multiboot function in hw/i386/multiboot.c in QEMU (aka Quick Emulator) allows local guest OS users to execute arbitrary code on the host via crafted multiboot header address values, which trigger an out-of-bounds write.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
8.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE:
190 (Integer Overflow or Wraparound)
References:
[qemu-devel] 20170905 [PATCH] multiboot: validate multiboot header address values (MLIST)
[oss-security] 20170907 CVE-2017-14167 Qemu: i386: multiboot OOB access while loading guest kernel image (MLIST)
100694 (BID)
DSA-3991 (DEBIAN)
RHSA-2017:3369 (REDHAT)
RHSA-2017:3368 (REDHAT)
RHSA-2017:3474 (REDHAT)
RHSA-2017:3473 (REDHAT)
RHSA-2017:3472 (REDHAT)
RHSA-2017:3471 (REDHAT)
RHSA-2017:3470 (REDHAT)
RHSA-2017:3466 (REDHAT)
USN-3575-1 (UBUNTU)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-15289
CVE: CVE-2017-15289
Id:
CVE-2017-15289
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15289
Comment
: The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors related to dst calculation.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CWE:
787 (Out-of-bounds Write)
References:
[qemu-devel] 20171011 [PATCH v2] cirrus: fix oob access in mode4and5 write functions (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1501290 (CONFIRM)
[oss-security] 20171012 CVE-2017-15289 Qemu: cirrus: OOB access issue in mode4and5 write functions (MLIST)
101262 (BID)
RHSA-2017:3369 (REDHAT)
RHSA-2017:3368 (REDHAT)
RHSA-2017:3474 (REDHAT)
RHSA-2017:3473 (REDHAT)
RHSA-2017:3472 (REDHAT)
RHSA-2017:3471 (REDHAT)
RHSA-2017:3470 (REDHAT)
RHSA-2017:3466 (REDHAT)
RHSA-2018:0516 (REDHAT)
USN-3575-1 (UBUNTU)
DSA-4213 (DEBIAN)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-2633
CVE: CVE-2017-2633
Id:
CVE-2017-2633
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2633
Comment
: An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
CVSSv2 Score:
4
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
SINGLE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P
CVSSv3 Score:
6.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
125 (Out-of-bounds Read)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2633 (CONFIRM)
[oss-security] 20170223 CVE-2017-2633 Qemu: VNC: memory corruption due to unchecked resolution limit (MLIST)
RHSA-2017:1856 (REDHAT)
RHSA-2017:1441 (REDHAT)
RHSA-2017:1206 (REDHAT)
RHSA-2017:1205 (REDHAT)
96417 (BID)
https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=bea60dd7679364493a0d7f5b54316c767cf894ef ()
https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=9f64916da20eea67121d544698676295bbb105a7 ()
CVE: CVE-2018-7550
CVE: CVE-2018-7550
Id:
CVE-2018-7550
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7550
Comment
: The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
CVSSv2 Score:
4.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
8.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE:
125 (Out-of-bounds Read)
References:
[qemu-devel] 20180228 [PATCH] multiboot: check mh_load_end_addr address field (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1549798 (CONFIRM)
103181 (BID)
[debian-lts-announce] 20180417 [SECURITY] [DLA 1351-1] qemu security update (MLIST)
[debian-lts-announce] 20180417 [SECURITY] [DLA 1350-1] qemu-kvm security update (MLIST)
RHSA-2018:1369 (REDHAT)
USN-3649-1 (UBUNTU)
DSA-4213 (DEBIAN)
RHSA-2018:2462 (REDHAT)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
https://github.com/orangecertcc/security-research/security/advisories/GHSA-f49v-45qp-cv53 ()
CVE: CVE-2018-11806
CVE: CVE-2018-11806
Id:
CVE-2018-11806
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11806
Comment
: m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
CVSSv2 Score:
7.2
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSSv3 Score:
8.2
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE:
787 (Out-of-bounds Write)
References:
https://www.zerodayinitiative.com/advisories/ZDI-18-567/ (MISC)
[qemu-devel] 20180605 [PATCH 1/2] slirp: correct size computation while concatenating mbuf (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1586245 (CONFIRM)
104400 (BID)
[oss-security] 20180607 CVE-2018-11806 Qemu: slirp: heap buffer overflow while reassembling fragmented datagrams (MLIST)
RHSA-2018:2462 (REDHAT)
RHSA-2018:2762 (REDHAT)
RHSA-2018:2822 (REDHAT)
RHSA-2018:2887 (REDHAT)
USN-3826-1 (UBUNTU)
[debian-lts-announce] 20190509 [SECURITY] [DLA 1781-1] qemu security update (MLIST)
DSA-4454 (DEBIAN)
20190531 [SECURITY] [DSA 4454-1] qemu security update (BUGTRAQ)
RHSA-2019:2892 (REDHAT)
CVE: CVE-2018-12617
CVE: CVE-2018-12617
Id:
CVE-2018-12617
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12617
Comment
: qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a crafted QMP command (including guest-file-read with a large count value) to the agent via the listening socket.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
190 (Integer Overflow or Wraparound)
References:
https://lists.gnu.org/archive/html/qemu-devel/2018-06/msg03385.html (MISC)
https://gist.github.com/fakhrizulkifli/c7740d28efa07dafee66d4da5d857ef6 (MISC)
104531 (BID)
44925 (EXPLOIT-DB)
USN-3826-1 (UBUNTU)
[debian-lts-announce] 20190228 [SECURITY] [DLA 1694-1] qemu security update (MLIST)
DSA-4454 (DEBIAN)
20190531 [SECURITY] [DSA 4454-1] qemu security update (BUGTRAQ)
CVE: CVE-2017-7471
CVE: CVE-2017-7471
Id:
CVE-2017-7471
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7471
Comment
: Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host directory. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.
CVSSv2 Score:
7.7
Access vector:
ADJACENT_NETWORK
Access complexity:
LOW
Authentication:
SINGLE
Confidentiality impact:
COMPLETE
Integrity impact:
COMPLETE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:A/AC:L/Au:S/C:C/I:C/A:C
CVSSv3 Score:
9
Attack vector:
ADJACENT_NETWORK
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE:
732 (Incorrect Permission Assignment for Critical Resource)
References:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7471 (CONFIRM)
[oss-security] 20170419 CVE-2017-7471 Qemu: 9p: virtfs allows guest to change filesystem attributes on host (MLIST)
GLSA-201706-03 (GENTOO)
97970 (BID)
https://git.qemu.org/?p=qemu.git%3Ba=commitdiff%3Bh=9c6b899f7a46893ab3b671e341a2234e9c0c060e (MISC)
CVE: CVE-2017-2630
CVE: CVE-2017-2630
Id:
CVE-2017-2630
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2630
Comment
: A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support. The flaw could occur while processing server's response to a 'NBD_OPT_LIST' request. A malicious NBD server could use this issue to crash a remote NBD client resulting in DoS or potentially execute arbitrary code on client host with privileges of the QEMU process.
CVSSv2 Score:
6.5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
SINGLE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSSv3 Score:
8.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
121 (Stack-based Buffer Overflow)
References:
[qemu-devel] 20170206 [PATCH 05/18] nbd/client: fix drop_sync (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2630 (CONFIRM)
[oss-security] 20170215 CVE-2017-2630 Qemu: nbd: oob stack write in client routine drop_sync (MLIST)
GLSA-201704-01 (GENTOO)
RHSA-2017:2392 (REDHAT)
96265 (BID)
https://bugzilla.redhat.com/show_bug.cgi?id=1422415 (CONFIRM)
https://github.com/qemu/qemu/commit/2563c9c6b8670400c48e562034b321a7cf3d9a85 (MISC)
CVE: CVE-2017-10806
CVE: CVE-2017-10806
Id:
CVE-2017-10806
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10806
Comment
: Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
787 (Out-of-bounds Write)
References:
[qemu-devel] 20170512 [PULL 2/6] usb-redir: fix stack overflow in usbredir_log_data (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1468496 (CONFIRM)
99475 (BID)
[oss-security] 20170707 CVE-2017-10806 Qemu: usb-redirect: stack buffer overflow in debug logging (MLIST)
DSA-3925 (DEBIAN)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-11334
CVE: CVE-2017-11334
Id:
CVE-2017-11334
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11334
Comment
: The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram block area.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
125 (Out-of-bounds Read)
References:
[qemu-devel] 20170713 [PULL 21/41] exec: use qemu_ram_ptr_length to access guest ram (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1471638 (CONFIRM)
[oss-security] 20170717 CVE-2017-11334 Qemu: exec: oob access during dma operation (MLIST)
99895 (BID)
DSA-3925 (DEBIAN)
RHSA-2017:3369 (REDHAT)
RHSA-2017:3474 (REDHAT)
RHSA-2017:3473 (REDHAT)
RHSA-2017:3472 (REDHAT)
RHSA-2017:3471 (REDHAT)
RHSA-2017:3470 (REDHAT)
RHSA-2017:3466 (REDHAT)
USN-3575-1 (UBUNTU)
CVE: CVE-2017-17381
CVE: CVE-2017-17381
Id:
CVE-2017-17381
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17381
Comment
: The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by unsetting vring alignment while updating Virtio rings.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CWE:
369 (Divide By Zero)
References:
[qemu-devel] 20171201 [PULL 6/7] virtio: check VirtQueue Vring object is set (MLIST)
[oss-security] 20171205 CVE-2017-17381 Qemu: virtio: divide by zero exception while updating rings (MLIST)
102059 (BID)
USN-3575-1 (UBUNTU)
DSA-4213 (DEBIAN)
CVE: CVE-2017-7493
CVE: CVE-2017-7493
Id:
CVE-2017-7493
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7493
Comment
: Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest.
CVSSv2 Score:
4.6
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
7.8
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE:
732 (Incorrect Permission Assignment for Critical Resource)
References:
[qemu-devel] 20170516 [PULL] 9pfs: local: forbid client access to metadata (CVE-2017-7493) (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1451709 (CONFIRM)
[oss-security] 20170517 CVE-2017-7493 Qemu: 9pfs: guest privilege escalation in virtfs mapped-file mode (MLIST)
98574 (BID)
GLSA-201706-03 (GENTOO)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-8112
CVE: CVE-2017-8112
Id:
CVE-2017-8112
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8112
Comment
: hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
6.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CWE:
835 (Loop with Unreachable Exit Condition ('Infinite Loop'))
References:
[qemu-devel] 20170425 Re: [PATCH] vmw_pvscsi: check message ring page count at initialisation (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1445621 (CONFIRM)
98015 (BID)
[oss-security] 20170426 CVE-2017-8112 Qemu: scsi: vmw_pvscsi: infinite loop in pvscsi_log2 (MLIST)
GLSA-201706-03 (GENTOO)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-9503
CVE: CVE-2017-9503
Id:
CVE-2017-9503
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9503
Comment
: QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:P
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
[qemu-devel] 20170606 [PATCH 7/7] megasas: always store SCSIRequest* into Megasas (MLIST)
[qemu-devel] 20170606 [PATCH 4/7] megasas: do not read DCMD opcode more than once (MLIST)
https://bugzilla.redhat.com/show_bug.cgi?id=1459477 (CONFIRM)
[oss-security] 20170608 CVE-2017-9503 Qemu: scsi: null pointer dereference while processing megasas command (MLIST)
99010 (BID)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
[debian-lts-announce] 20200726 [SECURITY] [DLA 2288-1] qemu security update (MLIST)
CVE: CVE-2017-12809
CVE: CVE-2017-12809
Id:
CVE-2017-12809
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12809
Comment
: QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
6.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CWE:
476 (NULL Pointer Dereference)
References:
[qemu-devel] 20170809 [Qemu-devel] [PATCH 1/2] IDE: Do not flush empty CDROM drives (MLIST)
[oss-security] 20170821 CVE-2017-12809 Qemu: ide: flushing of empty CDROM drives leads to NULL dereference (MLIST)
100451 (BID)
DSA-3991 (DEBIAN)
CVE: CVE-2017-15038
CVE: CVE-2017-15038
Id:
CVE-2017-15038
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15038
Comment
: Race condition in the v9fs_xattrwalk function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS users to obtain sensitive information from host heap memory via vectors related to reading extended attributes.
CVSSv2 Score:
1.9
Access vector:
LOCAL
Access complexity:
MEDIUM
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
NONE
CVSSv2 Vector:
AV:L/AC:M/Au:N/C:P/I:N/A:N
CVSSv3 Score:
5.6
Attack vector:
LOCAL
Attack complexity:
HIGH
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
NONE
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE:
362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'))
References:
[qemu-devel] 20171004 Re: [PATCH] 9pfs: use g_malloc0 to allocate space for xattr (MLIST)
[oss-security] 20171006 CVE-2017-15038 Qemu: 9p: virtfs: information disclosure when reading extended attributes (MLIST)
USN-3575-1 (UBUNTU)
DSA-4213 (DEBIAN)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-15119
CVE: CVE-2017-15119
Id:
CVE-2017-15119
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15119
Comment
: The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client could use this flaw to keep the NBD server from serving other requests, resulting in DoS.
CVSSv2 Score:
5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
8.6
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE:
400 (Uncontrolled Resource Consumption ('Resource Exhaustion'))
References:
https://lists.gnu.org/archive/html/qemu-devel/2017-11/msg05044.html (MISC)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15119 (CONFIRM)
http://www.openwall.com/lists/oss-security/2017/11/28/9 (MISC)
DSA-4213 (DEBIAN)
USN-3575-1 (UBUNTU)
RHSA-2018:1113 (REDHAT)
RHSA-2018:1104 (REDHAT)
102011 (BID)
CVE: CVE-2017-16845
CVE: CVE-2017-16845
Id:
CVE-2017-16845
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16845
Comment
: hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
CVSSv2 Score:
6.4
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:P
CVSSv3 Score:
10
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
HIGH
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
CWE:
20 (Improper Input Validation)
References:
[qemu-devel] 20171116 [PATCH v2] ps2: check PS2Queue indices in post_load routine (MLIST)
101923 (BID)
USN-3575-1 (UBUNTU)
USN-3649-1 (UBUNTU)
DSA-4213 (DEBIAN)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-18030
CVE: CVE-2017-18030
Id:
CVE-2017-18030
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18030
Comment
: The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to negative pitch.
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
4.4
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
HIGH
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE:
125 (Out-of-bounds Read)
References:
102520 (BID)
[oss-security] 20180115 CVE-2017-18030 Qemu: Out-of-bounds access in cirrus_invalidate_region routine (MLIST)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=f153b563f8cf121aebf5a2fff5f0110faf58ccb3 ()
CVE: CVE-2017-18043
CVE: CVE-2017-18043
Id:
CVE-2017-18043
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18043
Comment
: Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
CVSSv2 Score:
2.1
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:P
CVSSv3 Score:
5.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
190 (Integer Overflow or Wraparound)
References:
[oss-security] 20180119 CVE-2017-18043 Qemu: integer overflow in ROUND_UP macro could result in DoS (MLIST)
102759 (BID)
USN-3575-1 (UBUNTU)
DSA-4213 (DEBIAN)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
https://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=2098b073f398cd628c09c5a78537a6854 ()
CVE: CVE-2017-8309
CVE: CVE-2017-8309
Id:
CVE-2017-8309
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8309
Comment
: Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.
CVSSv2 Score:
7.8
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
7.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[qemu-devel] 20170428 [PATCH] audio: release capture buffers (MLIST)
98302 (BID)
GLSA-201706-03 (GENTOO)
RHSA-2017:2408 (REDHAT)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-8379
CVE: CVE-2017-8379
Id:
CVE-2017-8379
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8379
Comment
: Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.
CVSSv2 Score:
4.9
Access vector:
LOCAL
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
COMPLETE
CVSSv2 Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C
CVSSv3 Score:
6.5
Attack vector:
LOCAL
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
CHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CWE:
772 (Missing Release of Resource after Effective Lifetime)
References:
[qemu-devel] 20170428 [PATCH] input: limit kbd queue depth (MLIST)
98277 (BID)
[oss-security] 20170503 CVE-2017-8379 Qemu: input: host memory lekage via keyboard (MLIST)
GLSA-201706-03 (GENTOO)
RHSA-2017:2408 (REDHAT)
[debian-lts-announce] 20180906 [SECURITY] [DLA 1497-1] qemu security update (MLIST)
CVE: CVE-2017-8380
CVE: CVE-2017-8380
Id:
CVE-2017-8380
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8380
Comment
: Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors.
CVSSv2 Score:
7.5
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
NONE
Confidentiality impact:
PARTIAL
Integrity impact:
PARTIAL
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSSv3 Score:
9.8
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
NONE
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
HIGH
Integrity impact:
HIGH
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE:
119 (Improper Restriction of Operations within the Bounds of a Memory Buffer)
References:
https://lists.gnu.org/archive/html/qemu-devel/2017-04/msg04147.html (CONFIRM)
GLSA-201706-03 (GENTOO)
98303 (BID)
CVE: CVE-2017-13673
CVE: CVE-2017-13673
Id:
CVE-2017-13673
Reference:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13673
Comment
: The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (assertion failure) in the cpu_physical_memory_snapshot_get_dirty function.
CVSSv2 Score:
4
Access vector:
NETWORK
Access complexity:
LOW
Authentication:
SINGLE
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
PARTIAL
CVSSv2 Vector:
AV:N/AC:L/Au:S/C:N/I:N/A:P
CVSSv3 Score:
6.5
Attack vector:
NETWORK
Attack complexity:
LOW
Privileges required:
LOW
User interaction:
NONE
Scope:
UNCHANGED
Confidentiality impact:
NONE
Integrity impact:
NONE
Availability impact:
HIGH
CVSSv3 Vector:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE:
617 (Reachable Assertion)
References:
https://lists.gnu.org/archive/html/qemu-devel/2017-08/msg04685.html (CONFIRM)
100527 (BID)
[oss-security] 20170910 Re: CVE-2017-13673 Qemu: vga: reachable assert failure during during display update (MLIST)
RHSA-2018:1104 (REDHAT)
RHSA-2018:1113 (REDHAT)
openSUSE-SU-2019:1074 (SUSE)
https://git.qemu.org/gitweb.cgi?p=qemu.git%3Ba=commit%3Bh=bfc56535f793c557aa754c50213fc5f882e6482d ()
Content available only for registered users!
ovaldb@altx-soft.com