MGASA-2015-0368

Source
https://advisories.mageia.org/MGASA-2015-0368.html
Import Source
https://advisories.mageia.org/MGASA-2015-0368.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2015-0368
Related
Published
2015-09-15T14:55:06Z
Modified
2015-09-15T14:37:38Z
Summary
Updated qemu packages fix security vulnerabilities
Details

Updated qemu packages fix security vulnerabilities:

Qemu emulator built with the RTL8139 emulation support is vulnerable to an information leakage flaw. It could occur while processing network packets under RTL8139 controller's C+ mode of operation. A guest user could use this flaw to read uninitialised Qemu heap memory up to 65K bytes (CVE-2015-5165).

Qemu emulator built with the VNC display driver is vulnerable to an infinite loop issue. It could occur while processing a CLIENTCUTTEXT message with specially crafted payload message. A privileged guest user could use this flaw to crash the Qemu process on the host, resulting in DoS (CVE-2015-5239).

Qemu emulator built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing transmit descriptor data when sending a network packet. A privileged user inside guest could use this flaw to crash the Qemu instance resulting in DoS (CVE-2015-6815).

Qemu emulator built with the IDE disk and CD/DVD-ROM emulation support is vulnerable to a divide by zero issue. It could occur while executing an IDE command WINREADNATIVE_MAX to determine the maximum size of a drive. A privileged user inside guest could use this flaw to crash the Qemu instance resulting in DoS (CVE-2015-6855).

References
Credits

Affected packages

Mageia:4 / qemu

Package

Name
qemu
Purl
pkg:rpm/mageia/qemu?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.2-1.16.mga4

Ecosystem specific

{
    "section": "core"
}