VDB
MAGEIA-2015-149
MAGEIA-2015-149
PUBLISHED
Updated qemu packages fix security vulnerabilities: A denial of service flaw was found in the way QEMU handled malformed Physical Region Descriptor Table (PRDT) data sent to the host's IDE and/or AHCI controller emulation. A privileged guest user could use this flaw to crash the system (rhbz#1204919). It was found that the QEMU's websocket frame decoder processed incoming frames without limiting resources used to process the header and the payload. An attacker able to access a guest's VNC console could use this flaw to trigger a denial of service on the host by exhausting all available memory and CPU (CVE-2015-1779).
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mageia | qemu | 0, 1.6.2-1.9.mga4, 1.6.2-1.9.mga4 |
| Mageia | virtualbox | 5.0.6-1.mga5, 0 |
| Mageia | kmod-virtualbox | 0, 5.0.6-1.mga5 |
| Mageia | kmod-vboxadditions | 0, 5.0.6-1.mga5 |
Timeline
- Apr 15, 2015 CVE Updated
- Apr 15, 2015 CVE Published
References
- Updated qemu packages fix security vulnerabilities advisory
- Updated qemu packages fix security vulnerabilities issue
- Updated qemu packages fix security vulnerabilities issue
- Updated virtualbox packages with latest maintenance release advisory
- Updated virtualbox packages with latest maintenance release issue
- Updated virtualbox packages with latest maintenance release issue