Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE 12-SP5: SUSE-SU-2020:0845-1 Important: QEMU Buffer Overflow

suse
Calendar Grey April 1, 2020
Dist Suse Esm H88
SUSE Security Patch addresses severe vulnerabilities in qemu, improving both system integrity and performance for end-users.
An update that solves 6 vulnerabilities and has 6 fixes is now available

Summary

This update for qemu fixes the following issues: - CVE-2020-7039: Fixed a heap buffer overflow in tcp_emu() routine while emulating IRC and other protocols (bsc#1161066). - CVE-2019-15034: Fixed a buffer overflow in hw/display/bochs-display.c due to improper PCI config space allocation (bsc#1166379). - CVE-2020-1711: Fixed an out of bounds heap buffer access iscsi_co_block_status() routine which could have allowed a remote denial of service or arbitrary code with privileges of the QEMU process on the host (bsc#1166240). - CVE-2019-6778: Fixed a heap buffer overflow in tcp_emu() routine while emulating the identification protocol and copying message data to a socket buffer (bsc#1123156). - CVE-2020-8608: Fixed a heap buffer overflow in tcp_emu() routine while emulating IRC and

References

#1123156 #1154790 #1156642 #1156794 #1158880

#1161066 #1162161 #1162729 #1163018 #1165776

#1166240 #1166379

Cross- CVE-2019-15034 CVE-2019-20382 CVE-2019-6778

CVE-2020-1711 CVE-2020-7039 CVE-2020-8608

Affected Products:

SUSE Linux Enterprise Server 12-SP5

https://www.suse.com/security/cve/CVE-2019-15034.html

https://www.suse.com/security/cve/CVE-2019-20382.html

https://www.suse.com/security/cve/CVE-2019-6778.html

https://www.suse.com/security/cve/CVE-2020-1711.html

https://www.suse.com/security/cve/CVE-2020-7039.html

https://www.suse.com/security/cve/CVE-2020-8608.html

https://bugzilla.suse.com/1123156

https://bugzilla.suse.com/1154790

https://bugzilla.suse.com/1156642

https://bugzilla.suse.com/1156794

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0845-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here