Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69572
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2230-1)
Summary:The remote host is missing an update for the Debian 'qemu-kvm' package(s) announced via the DSA-2230-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'qemu-kvm' package(s) announced via the DSA-2230-1 advisory.

Vulnerability Insight:
Two vulnerabilities have been discovered in KVM, a solution for full virtualization on x86 hardware:

CVE-2011-0011

Setting the VNC password to an empty string silently disabled all authentication.

CVE-2011-1750

The virtio-blk driver performed insufficient validation of read/write I/O from the guest instance, which could lead to denial of service or privilege escalation.

The oldstable distribution (lenny) is not affected by this problem.

For the stable distribution (squeeze), this problem has been fixed in version 0.12.5+dfsg-5+squeeze1.

The unstable distribution (sid) will be fixed soon.

We recommend that you upgrade your qemu-kvm packages.

Affected Software/OS:
'qemu-kvm' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.4

CVSS Vector:
AV:A/AC:M/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-0011
42830
http://secunia.com/advisories/42830
43272
http://secunia.com/advisories/43272
43733
http://secunia.com/advisories/43733
44393
http://secunia.com/advisories/44393
70992
http://www.osvdb.org/70992
RHSA-2011:0345
http://rhn.redhat.com/errata/RHSA-2011-0345.html
USN-1063-1
http://ubuntu.com/usn/usn-1063-1
[oss-security] 20110110 CVE request: qemu-kvm: Setting VNC password to empty string silently disables all authentication
http://www.openwall.com/lists/oss-security/2011/01/10/3
[oss-security] 20110110 Re: CVE request: qemu-kvm: Setting VNC password to empty string silently disables all authentication
http://www.openwall.com/lists/oss-security/2011/01/11/1
[oss-security] 20110112 Re: CVE request: qemu-kvm: Setting VNC password to empty string silently disables all authentication
http://www.openwall.com/lists/oss-security/2011/01/12/2
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/697197
qemu-vnc-security-bypass(65215)
https://exchange.xforce.ibmcloud.com/vulnerabilities/65215
Common Vulnerability Exposure (CVE) ID: CVE-2011-1750
44132
http://secunia.com/advisories/44132
44658
http://secunia.com/advisories/44658
44660
http://secunia.com/advisories/44660
44900
http://secunia.com/advisories/44900
73756
http://www.osvdb.org/73756
DSA-2230
https://www.debian.org/security/2011/dsa-2230
FEDORA-2012-8604
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081972.html
RHSA-2011:0534
http://rhn.redhat.com/errata/RHSA-2011-0534.html
SUSE-SU-2011:0533
https://hermes.opensuse.org/messages/8572547
USN-1145-1
https://www.ubuntu.com/usn/USN-1145-1/
[Qemu-devel] 20110330 Re: virtio-blk.c handling of i/o which is not a 512 multiple
http://lists.gnu.org/archive/html/qemu-devel/2011-03/msg03019.html
[Qemu-devel] 20110330 virtio-blk.c handling of i/o which is not a 512 multiple
http://lists.gnu.org/archive/html/qemu-devel/2011-03/msg03015.html
http://git.kernel.org/?p=virt/kvm/qemu-kvm.git%3Ba=commitdiff%3Bh=52c050236eaa4f0b5e1d160cd66dc18106445c4d
kvm-virtioblk-priv-escalation(67062)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67062
openSUSE-SU-2011:0510
http://lists.opensuse.org/opensuse-updates/2011-05/msg00043.html
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.