This update for qemu fixes the following issues: Security vulnerabilities addressed: - CVE-2019-6778: Fixed an out-of-bounds access in slirp (bsc#1123156) - CVE-2018-16872: Fixed a host security vulnerability related to handling symlinks in usb-mtp (bsc#1119493) - CVE-2018-19489: Fixed a Denial-of-Service in virtfs (bsc#1117275) - CVE-2018-19364: Fixed an use-after-free vulnerability if virtfs interface is deliberately abused (bsc#1116717) - CVE-2018-18954: Fixed an out-of-bounds access performing PowerNV memory operations (bsc#1114957) - CVE-2017-13673: Fixed a reachable assert failure during during display update (bsc#1056386) - CVE-2017-13672: Fixed an out-of-bounds read access during display update (bsc#1056334)
#1056334 #1056386 #1084604 #1113231 #1114957
#1116717 #1117275 #1119493 #1121600 #1123156
Cross- CVE-2017-13672 CVE-2017-13673 CVE-2018-16872
CVE-2018-18954 CVE-2018-19364 CVE-2018-19489
CVE-2018-7858 CVE-2019-6778
Affected Products:
SUSE Linux Enterprise Server 12-SP3
SUSE Linux Enterprise Desktop 12-SP3
SUSE CaaS Platform ALL
SUSE CaaS Platform 3.0
https://www.suse.com/security/cve/CVE-2017-13672.html
https://www.suse.com/security/cve/CVE-2017-13673.html
https://www.suse.com/security/cve/CVE-2018-16872.html
https://www.suse.com/security/cve/CVE-2018-18954.html
https://www.suse.com/security/cve/CVE-2018-19364.html
https://www.suse.com/security/cve/CVE-2018-19489.html
https://www.suse.com/security/cve/CVE-2018-7858.html
Get the latest Linux and open source security news straight to your inbox.