Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.703259
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-3259-1)
Summary:The remote host is missing an update for the Debian 'qemu' package(s) announced via the DSA-3259-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'qemu' package(s) announced via the DSA-3259-1 advisory.

Vulnerability Insight:
Several vulnerabilities were discovered in the qemu virtualisation solution:

CVE-2014-9718

It was discovered that the IDE controller emulation is susceptible to denial of service.

CVE-2015-1779

Daniel P. Berrange discovered a denial of service vulnerability in the VNC web socket decoder.

CVE-2015-2756

Jan Beulich discovered that unmediated PCI command register could result in denial of service.

CVE-2015-3456

Jason Geffner discovered a buffer overflow in the emulated floppy disk drive, resulting in the potential execution of arbitrary code.

For the oldstable distribution (wheezy), these problems have been fixed in version 1.1.2+dfsg-6a+deb7u7 of the qemu source package and in version 1.1.2+dfsg-6+deb7u7 of the qemu-kvm source package. Only CVE-2015-3456 affects oldstable.

For the stable distribution (jessie), these problems have been fixed in version 1:2.1+dfsg-12.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your qemu packages.

Affected Software/OS:
'qemu' package(s) on Debian 8.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-9718
73316
http://www.securityfocus.com/bid/73316
DSA-3259
http://www.debian.org/security/2015/dsa-3259
[oss-security] 20150420 Re: CVE request Qemu: malicious PRDT flow from guest to host
http://openwall.com/lists/oss-security/2015/04/20/7
http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=3251bdcf1c67427d964517053c3d185b46e618e8
Common Vulnerability Exposure (CVE) ID: CVE-2015-1779
1033975
http://www.securitytracker.com/id/1033975
73303
http://www.securityfocus.com/bid/73303
FEDORA-2015-5482
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154656.html
FEDORA-2015-5541
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155196.html
GLSA-201602-01
https://security.gentoo.org/glsa/201602-01
RHSA-2015:1931
http://rhn.redhat.com/errata/RHSA-2015-1931.html
RHSA-2015:1943
http://rhn.redhat.com/errata/RHSA-2015-1943.html
SUSE-SU-2015:0870
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00033.html
SUSE-SU-2015:0896
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00042.html
USN-2608-1
http://www.ubuntu.com/usn/USN-2608-1
[Qemu-devel] 20150323 [PATCH 0/2] CVE-2015-1779: fix denial of service in VNC websockets
https://lists.gnu.org/archive/html/qemu-devel/2015-03/msg04894.html
[Qemu-devel] 20150323 [PATCH 1/2] CVE-2015-1779: incrementally decode websocket frames
https://lists.gnu.org/archive/html/qemu-devel/2015-03/msg04896.html
[Qemu-devel] 20150323 [PATCH 2/2] CVE-2015-1779: limit size of HTTP headers from websockets clients
https://lists.gnu.org/archive/html/qemu-devel/2015-03/msg04895.html
[oss-security] 20150324 CVE-2015-1779 qemu: vnc: insufficient resource limiting in VNC websockets decoder
http://www.openwall.com/lists/oss-security/2015/03/24/9
[oss-security] 20150409 Re: CVE-2015-1779 qemu: vnc: insufficient resource limiting in VNC websockets decoder
http://www.openwall.com/lists/oss-security/2015/04/09/6
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-2756
BugTraq ID: 72577
http://www.securityfocus.com/bid/72577
Debian Security Information: DSA-3259 (Google Search)
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154574.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155198.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154579.html
https://security.gentoo.org/glsa/201504-04
http://lists.nongnu.org/archive/html/qemu-devel/2015-03/msg06179.html
http://www.securitytracker.com/id/1031998
SuSE Security Announcement: openSUSE-SU-2015:0732 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00014.html
Common Vulnerability Exposure (CVE) ID: CVE-2015-3456
BugTraq ID: 74640
http://www.securityfocus.com/bid/74640
Debian Security Information: DSA-3262 (Google Search)
http://www.debian.org/security/2015/dsa-3262
Debian Security Information: DSA-3274 (Google Search)
http://www.debian.org/security/2015/dsa-3274
https://www.exploit-db.com/exploits/37053/
http://lists.fedoraproject.org/pipermail/package-announce/2015-May/158072.html
https://security.gentoo.org/glsa/201604-03
https://security.gentoo.org/glsa/201612-27
HPdes Security Advisory: HPSBMU03336
http://marc.info/?l=bugtraq&m=143229451215900&w=2
HPdes Security Advisory: HPSBMU03349
http://marc.info/?l=bugtraq&m=143387998230996&w=2
HPdes Security Advisory: SSRT102076
http://venom.crowdstrike.com/
https://www.arista.com/en/support/advisories-notices/security-advisories/1128-security-advisory-10
RedHat Security Advisories: RHSA-2015:0998
http://rhn.redhat.com/errata/RHSA-2015-0998.html
RedHat Security Advisories: RHSA-2015:0999
http://rhn.redhat.com/errata/RHSA-2015-0999.html
RedHat Security Advisories: RHSA-2015:1000
http://rhn.redhat.com/errata/RHSA-2015-1000.html
RedHat Security Advisories: RHSA-2015:1001
http://rhn.redhat.com/errata/RHSA-2015-1001.html
RedHat Security Advisories: RHSA-2015:1002
http://rhn.redhat.com/errata/RHSA-2015-1002.html
RedHat Security Advisories: RHSA-2015:1003
http://rhn.redhat.com/errata/RHSA-2015-1003.html
RedHat Security Advisories: RHSA-2015:1004
http://rhn.redhat.com/errata/RHSA-2015-1004.html
RedHat Security Advisories: RHSA-2015:1011
http://rhn.redhat.com/errata/RHSA-2015-1011.html
http://www.securitytracker.com/id/1032306
http://www.securitytracker.com/id/1032311
http://www.securitytracker.com/id/1032917
SuSE Security Announcement: SUSE-SU-2015:0889 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00009.html
SuSE Security Announcement: SUSE-SU-2015:0896 (Google Search)
SuSE Security Announcement: SUSE-SU-2015:0923 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00018.html
SuSE Security Announcement: SUSE-SU-2015:0927 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00019.html
SuSE Security Announcement: SUSE-SU-2015:0929 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00021.html
SuSE Security Announcement: openSUSE-SU-2015:0893 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00013.html
SuSE Security Announcement: openSUSE-SU-2015:0894 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00014.html
SuSE Security Announcement: openSUSE-SU-2015:0983 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00001.html
SuSE Security Announcement: openSUSE-SU-2015:1400 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-08/msg00021.html
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.