Description: | Description:
The remote host is missing an update to kvm announced via advisory FEDORA-2008-11705.
KVM (for Kernel-based Virtual Machine) is a full virtualization solution for Linux on x86 hardware.
Using KVM, one can run multiple virtual machines running unmodified Linux or Windows images. Each virtual machine has private virtualized hardware: a network card, disk, graphics adapter, etc.
Update Information:
ChangeLog:
* Mon Dec 22 2008 Glauber Costa - 65-15.fc9 - Fixed CVE 2008-2382. * Thu Dec 4 2008 Glauber Costa - 65-14.fc9 - Fixed bug that corrupted gnome-panel #474702 * Tue Dec 2 2008 Glauber Costa - 65-12.fc9 - Properly set flags for interrupt return #464304 * Tue Nov 11 2008 Glauber Costa - 65-11.fc9 - Fix CVE-2008-4539 #448525
References:
[ 1 ] Bug #477636 - CVE-2008-2382 qemu/kvm: remote DoS (infinite loop) via specially-crafted VNC message received by the domain https://bugzilla.redhat.com/show_bug.cgi?id=477636 [ 2 ] Bug #466890 - CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320 https://bugzilla.redhat.com/show_bug.cgi?id=466890
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update kvm' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-11705
Risk factor : High
CVSS Score: 7.2
|