From: Mageia Updates <buildsystem-daemon@mageia.org>To: updates-announce@ml.mageia.orgSubject: [updates-announce] MGASA-2015-0368: Updated qemu packages fix security vulnerabilitiesDate: 2015年9月15日 16:55:37 +0200Message-ID: <20150915145538.0ACBC5A01A@valstar.mageia.org>MGASA-2015-0368 - Updated qemu packages fix security vulnerabilities Publication date: 15 Sep 2015 URL: http://advisories.mageia.org/MGASA-2015-0368.html Type: security Affected Mageia releases: 4 CVE: CVE-2015-5165, CVE-2015-5239, CVE-2015-6815, CVE-2015-6855 Description: Updated qemu packages fix security vulnerabilities: Qemu emulator built with the RTL8139 emulation support is vulnerable to an information leakage flaw. It could occur while processing network packets under RTL8139 controller's C+ mode of operation. A guest user could use this flaw to read uninitialised Qemu heap memory up to 65K bytes (CVE-2015-5165). Qemu emulator built with the VNC display driver is vulnerable to an infinite loop issue. It could occur while processing a CLIENT_CUT_TEXT message with specially crafted payload message. A privileged guest user could use this flaw to crash the Qemu process on the host, resulting in DoS (CVE-2015-5239). Qemu emulator built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing transmit descriptor data when sending a network packet. A privileged user inside guest could use this flaw to crash the Qemu instance resulting in DoS (CVE-2015-6815). Qemu emulator built with the IDE disk and CD/DVD-ROM emulation support is vulnerable to a divide by zero issue. It could occur while executing an IDE command WIN_READ_NATIVE_MAX to determine the maximum size of a drive. A privileged user inside guest could use this flaw to crash the Qemu instance resulting in DoS (CVE-2015-6855). References: - https://bugs.mageia.org/show_bug.cgi?id=16604 - https://lists.fedoraproject.org/pipermail/package-announc... - http://openwall.com/lists/oss-security/2015/09/02/7 - http://openwall.com/lists/oss-security/2015/09/05/5 - http://openwall.com/lists/oss-security/2015/09/10/2 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5165 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5239 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6815 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6855 SRPMS: - 4/core/qemu-1.6.2-1.16.mga4