Gentoo Archives: gentoo-announce

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201602-01 ] QEMU: Multiple vulnerabilities
Date: Thu, 04 Feb 2016 09:34:12
Message-Id: 56B317A6.8000409@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201602-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: QEMU: Multiple vulnerabilities
9 Date: February 04, 2016
10 Bugs: #544328, #549404, #557206, #558416, #559656, #560422,
11 #560550, #560760, #566792, #567144, #567828, #567868,
12 #568214, #568226, #568246, #569646, #570110, #570988,
13 #571562, #571564, #571566
14 ID: 201602-01
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Multiple vulnerabilities have been found in QEMU, the worst of which
22 may allow a remote attacker to cause a Denial of Service or gain
23 elevated privileges from a guest VM.
24
25 Background
26 ==========
27
28 QEMU is a generic and open source machine emulator and virtualizer.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 app-emulation/qemu < 2.5.0-r1 >= 2.5.0-r1
37
38 Description
39 ===========
40
41 Multiple vulnerabilities have been discovered in QEMU. Please review
42 the CVE identifiers referenced below for details.
43
44 Impact
45 ======
46
47 A remote attacker might cause a Denial of Service or gain escalated
48 privileges from a guest VM.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All QEMU users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=app-emulation/qemu-2.5.0-r1"
62
63 References
64 ==========
65
66 [ 1 ] CVE-2015-1779
67 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-1779
68 [ 2 ] CVE-2015-3456
69 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3456
70 [ 3 ] CVE-2015-5225
71 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5225
72 [ 4 ] CVE-2015-5278
73 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5278
74 [ 5 ] CVE-2015-5279
75 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5279
76 [ 6 ] CVE-2015-5745
77 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-5745
78 [ 7 ] CVE-2015-6815
79 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6815
80 [ 8 ] CVE-2015-6855
81 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-6855
82 [ 9 ] CVE-2015-7295
83 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7295
84 [ 10 ] CVE-2015-7504
85 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7504
86 [ 11 ] CVE-2015-7512
87 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7512
88 [ 12 ] CVE-2015-7549
89 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7549
90 [ 13 ] CVE-2015-8345
91 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8345
92 [ 14 ] CVE-2015-8504
93 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8504
94 [ 15 ] CVE-2015-8556
95 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8556
96 [ 16 ] CVE-2015-8558
97 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8558
98 [ 17 ] CVE-2015-8567
99 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8567
100 [ 18 ] CVE-2015-8568
101 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8568
102 [ 19 ] CVE-2015-8666
103 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8666
104 [ 20 ] CVE-2015-8701
105 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8701
106 [ 21 ] CVE-2015-8743
107 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8743
108 [ 22 ] CVE-2015-8744
109 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8744
110 [ 23 ] CVE-2015-8745
111 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-8745
112 [ 24 ] CVE-2016-1568
113 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1568
114
115 Availability
116 ============
117
118 This GLSA and any updates to it are available for viewing at
119 the Gentoo Security Website:
120
121 https://security.gentoo.org/glsa/201602-01
122
123 Concerns?
124 =========
125
126 Security is a primary focus of Gentoo Linux and ensuring the
127 confidentiality and security of our users' machines is of utmost
128 importance to us. Any security concerns should be addressed to
129 security@g.o or alternatively, you may file a bug at
130 https://bugs.gentoo.org.
131
132 License
133 =======
134
135 Copyright 2016 Gentoo Foundation, Inc; referenced text
136 belongs to its owner(s).
137
138 The contents of this document are licensed under the
139 Creative Commons - Attribution / Share Alike license.
140
141 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature