Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.70056
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 2282-1 (qemu-kvm)
Zusammenfassung:The remote host is missing an update to qemu-kvm;announced via advisory DSA 2282-1.
Beschreibung:Summary:
The remote host is missing an update to qemu-kvm
announced via advisory DSA 2282-1.

Vulnerability Insight:
Two vulnerabilities have been discovered in KVM, a solution for full
virtualization on x86 hardware:

CVE-2011-2212

Nelson Elhage discovered a buffer overflow in the virtio subsystem,
which could lead to denial of service or privilege escalation.

CVE-2011-2527

Andrew Griffiths discovered that group privileges were
insufficiently dropped when started with -runas option, resulting
in privilege escalation.

For the stable distribution (squeeze), this problem has been fixed in
version 0.12.5+dfsg-5+squeeze6.

For the unstable distribution (sid), this problem has been fixed in
version 0.14.1+dfsg-3.

Solution:
We recommend that you upgrade your qemu-kvm packages.

CVSS Score:
7.4

CVSS Vector:
AV:A/AC:M/Au:S/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-2212
Debian Security Information: DSA-2282 (Google Search)
https://www.debian.org/security/2011/dsa-2282
http://www.osvdb.org/74751
RedHat Security Advisories: RHSA-2011:0919
http://rhn.redhat.com/errata/RHSA-2011-0919.html
http://secunia.com/advisories/45158
http://secunia.com/advisories/45170
http://secunia.com/advisories/45187
http://secunia.com/advisories/45188
http://secunia.com/advisories/45301
http://secunia.com/advisories/45354
SuSE Security Announcement: SUSE-SU-2011:0806 (Google Search)
https://hermes.opensuse.org/messages/9605323
SuSE Security Announcement: openSUSE-SU-2011:0803 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00007.html
http://ubuntu.com/usn/usn-1165-1
Common Vulnerability Exposure (CVE) ID: CVE-2011-2527
BugTraq ID: 48659
http://www.securityfocus.com/bid/48659
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081972.html
http://www.openwall.com/lists/oss-security/2011/07/12/5
http://www.openwall.com/lists/oss-security/2011/07/12/15
http://www.osvdb.org/74752
RedHat Security Advisories: RHSA-2011:1531
http://rhn.redhat.com/errata/RHSA-2011-1531.html
http://secunia.com/advisories/45419
http://secunia.com/advisories/47157
http://secunia.com/advisories/47992
SuSE Security Announcement: openSUSE-SU-2012:0207 (Google Search)
http://lists.opensuse.org/opensuse-updates/2012-02/msg00009.html
http://ubuntu.com/usn/usn-1177-1
XForce ISS Database: qemu-runas-priv-escalation(68539)
https://exchange.xforce.ibmcloud.com/vulnerabilities/68539
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.