Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2019:0471-1 Important: QEMU Buffer Overflow And DoS Issues

suse
Calendar Grey February 22, 2019
Dist Suse Esm H88
SUSE has released a vital security patch for QEMU, tackling critical concerns such as buffer overflow risks and potential denial of service exploits.
An update that fixes four vulnerabilities is now available

Summary

This update for qemu fixes the following issues: Security issue fixed: - CVE-2019-6778: Fixed a heap buffer overflow issue in the SLiRP networking implementation (bsc#1123156). - CVE-2018-16872: Fixed a host security vulnerability related to handling symlinks in usb-mtp (bsc#1119493). - CVE-2018-19489: Fixed a denial of service vulnerability in virtfs (bsc#1117275). - CVE-2018-19364: Fixed a use-after-free if the virtfs interface resulting in a denial of service (bsc#1116717). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-471=1 Package List:

References

#1116717 #1117275 #1119493 #1123156

Cross- CVE-2018-16872 CVE-2018-19364 CVE-2018-19489

CVE-2019-6778

Affected Products:

SUSE Linux Enterprise Server 12-SP1-LTSS

https://https://www.suse.com/security/cve/CVE-2018-16872.html

https://www.suse.com/security/cve/CVE-2018-19364.html

https://www.suse.com/security/cve/CVE-2018-19489.html

https://www.suse.com/security/cve/CVE-2019-6778.html

https://bugzilla.suse.com/1116717

https://bugzilla.suse.com/1117275

https://bugzilla.suse.com/1119493

https://bugzilla.suse.com/1123156

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0471-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here