Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 534
Alerts This Week
Warning Icon 1 534

Debian LTS DLA-1071-1 Medium: qemu-kvm Denial of Service Issues

debian lts
Calendar Grey August 28, 2017
Scroller Debian Lts
Enhance qemu-kvm to address various denial of service vulnerabilities in Debian LTS. Ensure your system's security and maintain updates right now.
Multiple vulnerabilities were discovered in qemu-kvm, a full virtualization solution for Linux hosts on x86 hardware with x86 guests based on the Quick Emulator(Qemu)

Summary

Denial of service via infinite loop in the USB OHCI emulation

CVE-2017-8309

Denial of service via VNC audio capture

CVE-2017-10664

Denial of service in qemu-nbd server, qemu-io and qemu-img.

CVE-2017-11434

Denial of service via a crafted DHCP options string

For Debian 7 "Wheezy", these problems have been fixed in version
1.1.2+dfsg-6+deb7u23.

We recommend that you upgrade your qemu-kvm packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
medium
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: qemu-kvm
Version: 1.1.2+dfsg-6+deb7u23
CVE ID: CVE-2017-6505 CVE-2017-8309 CVE-2017-10664 CVE-2017-11434

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.