Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.882309
Categoría:CentOS Local Security Checks
Título:CentOS Update for libcacard CESA-2015:1943 centos7
Resumen:Check the version of libcacard
Descripción:Summary:
Check the version of libcacard

Vulnerability Insight:
KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

It was found that the QEMU's websocket frame decoder processed incoming
frames without limiting resources used to process the header and the
payload. An attacker able to access a guest's VNC console could use this
flaw to trigger a denial of service on the host by exhausting all available
memory and CPU. (CVE-2015-1779)

This issue was discovered by Daniel P. Berrange of Red Hat.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.

Affected Software/OS:
libcacard on CentOS 7

Solution:
Please install the updated packages.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2015-1779
1033975
http://www.securitytracker.com/id/1033975
73303
http://www.securityfocus.com/bid/73303
DSA-3259
http://www.debian.org/security/2015/dsa-3259
FEDORA-2015-5482
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154656.html
FEDORA-2015-5541
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155196.html
GLSA-201602-01
https://security.gentoo.org/glsa/201602-01
RHSA-2015:1931
http://rhn.redhat.com/errata/RHSA-2015-1931.html
RHSA-2015:1943
http://rhn.redhat.com/errata/RHSA-2015-1943.html
SUSE-SU-2015:0870
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00033.html
SUSE-SU-2015:0896
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00042.html
USN-2608-1
http://www.ubuntu.com/usn/USN-2608-1
[Qemu-devel] 20150323 [PATCH 0/2] CVE-2015-1779: fix denial of service in VNC websockets
https://lists.gnu.org/archive/html/qemu-devel/2015-03/msg04894.html
[Qemu-devel] 20150323 [PATCH 1/2] CVE-2015-1779: incrementally decode websocket frames
https://lists.gnu.org/archive/html/qemu-devel/2015-03/msg04896.html
[Qemu-devel] 20150323 [PATCH 2/2] CVE-2015-1779: limit size of HTTP headers from websockets clients
https://lists.gnu.org/archive/html/qemu-devel/2015-03/msg04895.html
[oss-security] 20150324 CVE-2015-1779 qemu: vnc: insufficient resource limiting in VNC websockets decoder
http://www.openwall.com/lists/oss-security/2015/03/24/9
[oss-security] 20150409 Re: CVE-2015-1779 qemu: vnc: insufficient resource limiting in VNC websockets decoder
http://www.openwall.com/lists/oss-security/2015/04/09/6
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
CopyrightCopyright (C) 2015 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.