Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Scientific Linux: SLSA-2014:0420-1 Moderate: Qemu-KVM Security Update

Scientific Large Esm H446
Moderate: qemu-kvm security update
Date: Tue, 22 Apr 2014 09:35:54 -0500
Reply-To: Bonnie King 
Sender: Security Errata for Scientific Linux
 
From: Bonnie King 
Subject: FASTBUGS for SL 6x i386, x86_64 now available
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.
In-Reply-To: <534D60CF.3070207@fnal.gov>
MIME-Version: 1.0

The following FASTBUGS have been uploaded to

i386:
mod_perl-2.0.4-11.el6_5.i686.rpm
mod_perl-devel-2.0.4-11.el6_5.i686.rpm

x86_64:
mod_perl-2.0.4-11.el6_5.x86_64.rpm
mod_perl-devel-2.0.4-11.el6_5.i686.rpm
mod_perl-devel-2.0.4-11.el6_5.x86_64.rpm
Date: Tue, 22 Apr 2014 21:26:58 +0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Moderate: qemu-kvm on SL6.x i386/x86_64
MIME-Version: 1.0

Synopsis: Moderate: qemu-kvm security update
Advisory ID: SLSA-2014:0420-1
Issue Date: 2014-04-22
CVE Numbers: CVE-2014-0142
 CVE-2014-0148
 CVE-2014-0146
 CVE-2014-0150
 CVE-2014-0147
 CVE-2014-0145
 CVE-2014-0143
 CVE-2014-0144
--

Multiple integer overflow, input validation, logic error, and buffer
overflow flaws were discovered in various QEMU block drivers. An attacker
able to modify a disk image file loaded by a guest could use these flaws
to crash the guest, or corrupt QEMU process memory on the host,
potentially resulting in arbitrary code execution on the host with the
privileges of the QEMU process. (CVE-2014-0143, CVE-2014-0144,
CVE-2014-0145, CVE-2014-0147)

A buffer overflow flaw was found in the way the virtio_net_handle_mac()
function of QEMU processed guest requests to update the table of MAC
addresses. A privileged guest user could use this flaw to corrupt QEMU
process memory on the host, potentially resulting in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2014-0150)

A divide-by-zero flaw was found in the seek_to_sector() function of the
parallels block driver in QEMU. An attacker able to modify a disk image
file loaded by a guest could use this flaw to crash the guest.
(CVE-2014-0142)

A NULL pointer dereference flaw was found in the QCOW2 block driver in
QEMU. An attacker able to modify a disk image file loaded by a guest could
use this flaw to crash the guest. (CVE-2014-0146)

It was found that the block driver for Hyper-V VHDX images did not
correctly calculate BAT (Block Allocation Table) entries due to a missing
bounds check. An attacker able to modify a disk image file loaded by a
guest could use this flaw to crash the guest. (CVE-2014-0148)

After installing this update, shut down all running virtual machines. Once
all virtual machines have shut down, start them again for this update to
take effect.
--

SL6
 x86_64
 qemu-guest-agent-0.12.1.2-2.415.el6_5.8.x86_64.rpm
 qemu-img-0.12.1.2-2.415.el6_5.8.x86_64.rpm
 qemu-kvm-0.12.1.2-2.415.el6_5.8.x86_64.rpm
 qemu-kvm-debuginfo-0.12.1.2-2.415.el6_5.8.x86_64.rpm
 qemu-kvm-tools-0.12.1.2-2.415.el6_5.8.x86_64.rpm
 i386
 qemu-guest-agent-0.12.1.2-2.415.el6_5.8.i686.rpm
 qemu-kvm-debuginfo-0.12.1.2-2.415.el6_5.8.i686.rpm

- Scientific Linux Development Team