Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian: DSA-3469-1 Critical QEMU DoS And Buffer Overflow Advisories

debian
Calendar Grey February 8, 2016
Debian Logo
Ubuntu Security Notice USN-1234-1 resolves multiple vulnerabilities in kvm, essential for maintaining system integrity.
Several vulnerabilities were discovered in qemu, a full virtualization solution on x86 hardware

Summary

CVE-2015-7295

Jason Wang of Red Hat Inc. discovered that the Virtual Network
Device support is vulnerable to denial-of-service (via resource
exhaustion), that could occur when receiving large packets.

CVE-2015-7504

Qinghao Tang of Qihoo 360 Inc. and Ling Liu of Qihoo 360 Inc.
discovered that the PC-Net II ethernet controller is vulnerable to
a heap-based buffer overflow that could result in
denial-of-service (via application crash) or arbitrary code
execution.

CVE-2015-7512

Ling Liu of Qihoo 360 Inc. and Jason Wang of Red Hat Inc.
discovered that the PC-Net II ethernet controller is vulnerable to
a buffer overflow that could result in denial-of-service (via
application crash) or arbitrary code execution.

CVE-2015-8345

Qinghao Tang of Qihoo 360 Inc. discovered that the eepro100
emulator contains a flaw that could lead to an infinite loop when
processing Command Blocks, eventually resulting in
denial-of-service (via application crash).

CVE-2...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: qemu
CVE ID: CVE-2015-7295 CVE-2015-7504 CVE-2015-7512 CVE-2015-8345

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here