Description: | Description:
The remote host is missing an update to kvm announced via advisory FEDORA-2008-11727.
KVM (for Kernel-based Virtual Machine) is a full virtualization solution for Linux on x86 hardware.
Using KVM, one can run multiple virtual machines running unmodified Linux or Windows images. Each virtual machine has private virtualized hardware: a network card, disk, graphics adapter, etc.
Update Information:
ChangeLog:
* Mon Dec 22 2008 Glauber Costa - 74-10 - Fixed CVE 2008-2382. * Thu Dec 4 2008 Glauber Costa - 74-9 - Fixed bug that corrupted gnome-panel #474703 * Tue Dec 2 2008 Glauber Costa - 74-8 - Properly set flags for interrupt return #474059 * Mon Nov 24 2008 Glauber Costa - 74-7 - added upstream patch kvm-restore-option-rom.patch - #470561 * Tue Nov 11 2008 Glauber Costa - 74-6 - Fix cirrus vulnerability (CVE-2008-4539) - #471055 References:
[ 1 ] Bug #477636 - CVE-2008-2382 qemu/kvm: remote DoS (infinite loop) via specially-crafted VNC message received by the domain https://bugzilla.redhat.com/show_bug.cgi?id=477636
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update kvm' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-11727
Risk factor : High
CVSS Score: 7.2
|