Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.840695
Kategorie:Ubuntu Local Security Checks
Titel:Ubuntu Update for qemu-kvm USN-1165-1
Zusammenfassung:Ubuntu Update for Linux kernel vulnerabilities USN-1165-1
Beschreibung:Summary:
Ubuntu Update for Linux kernel vulnerabilities USN-1165-1

Vulnerability Insight:
Nelson Elhage discoverd that QEMU did not properly validate certain
virtqueue requests from the guest. An attacker could exploit this to cause
a denial of service of the guest or possibly execute code with the
privileges of the user invoking the program. (CVE-2011-2212)

Stefan Hajnoczi discovered that QEMU did not properly perform integer
comparisons when performing virtqueue input validation. An attacker could
exploit this to cause a denial of service of the guest or possibly execute
code with the privileges of the user invoking the program. (CVE-2011-2512)

When using QEMU with libvirt or virtualization management software based on
libvirt such as Eucalyptus and OpenStack, QEMU guests are individually
isolated by an AppArmor profile by default in Ubuntu.

Affected Software/OS:
qemu-kvm on Ubuntu 11.04,
Ubuntu 10.10,
Ubuntu 10.04 LTS

Solution:
Please Install the Updated Packages.

CVSS Score:
7.4

CVSS Vector:
AV:A/AC:M/Au:S/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-2212
Debian Security Information: DSA-2282 (Google Search)
https://www.debian.org/security/2011/dsa-2282
http://www.osvdb.org/74751
RedHat Security Advisories: RHSA-2011:0919
http://rhn.redhat.com/errata/RHSA-2011-0919.html
http://secunia.com/advisories/45158
http://secunia.com/advisories/45170
http://secunia.com/advisories/45187
http://secunia.com/advisories/45188
http://secunia.com/advisories/45301
http://secunia.com/advisories/45354
SuSE Security Announcement: SUSE-SU-2011:0806 (Google Search)
https://hermes.opensuse.org/messages/9605323
SuSE Security Announcement: openSUSE-SU-2011:0803 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00007.html
http://ubuntu.com/usn/usn-1165-1
Common Vulnerability Exposure (CVE) ID: CVE-2011-2512
Debian Security Information: DSA-2270 (Google Search)
https://www.debian.org/security/2011/dsa-2270
http://www.openwall.com/lists/oss-security/2011/06/28/13
http://www.openwall.com/lists/oss-security/2011/06/29/15
http://secunia.com/advisories/44458
http://secunia.com/advisories/44648
CopyrightCopyright (c) 2011 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.