MGASA-2015-0397

Source
https://advisories.mageia.org/MGASA-2015-0397.html
Import Source
https://advisories.mageia.org/MGASA-2015-0397.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2015-0397
Related
Published
2015-10-13T22:40:25Z
Modified
2015-10-13T22:35:21Z
Summary
Updated qemu packages fixes security vulnerabilities
Details

Qinghao Tang of QIHU 360 Inc. discovered an infinite loop issue in the NE2000 NIC emulation. A privileged guest user could use this flaw to mount a denial of service (QEMU process crash). (CVE-2015-5278)

Qinghao Tang of QIHU 360 Inc. discovered a heap buffer overflow flaw in the NE2000 NIC emulation. A privileged guest user could use this flaw to mount a denial of service (QEMU process crash), or potentially to execute arbitrary code on the host with the privileges of the hosting QEMU process. (CVE-2015-5279)

A flaw has been discovered in the QEMU emulator built with Virtual Network Device(virtio-net) support. If the guest's virtio-net driver did not support big or mergeable receive buffers, an issue could occur while receiving large packets over the tuntap/ macvtap interfaces. An attacker on the local network could use this flaw to disable the guest's networking; the user could send a large number of jumbo frames to the guest, which could exhaust all receive buffers, and lead to a denial of service. (CVE-2015-7295)

References
Credits

Affected packages

Mageia:5 / qemu

Package

Name
qemu
Purl
pkg:rpm/mageia/qemu?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.3-2.7.mga5

Ecosystem specific

{
    "section": "core"
}