Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69978
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2270-1)
Summary:The remote host is missing an update for the Debian 'qemu-kvm' package(s) announced via the DSA-2270-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'qemu-kvm' package(s) announced via the DSA-2270-1 advisory.

Vulnerability Insight:
It was discovered that incorrect sanitising of virtio queue commands in KVM, a solution for full virtualization on x86 hardware, could lead to denial of service or the execution of arbitrary code.

The oldstable distribution (lenny) is not affected by this problem.

For the stable distribution (squeeze), this problem has been fixed in version 0.12.5+dfsg-5+squeeze4.

For the unstable distribution (sid), this problem has been fixed in version 0.14.1+dfsg-2.

We recommend that you upgrade your qemu-kvm packages.

Affected Software/OS:
'qemu-kvm' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:A/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-2512
44458
http://secunia.com/advisories/44458
44648
http://secunia.com/advisories/44648
45158
http://secunia.com/advisories/45158
45170
http://secunia.com/advisories/45170
45301
http://secunia.com/advisories/45301
74751
http://www.osvdb.org/74751
DSA-2270
https://www.debian.org/security/2011/dsa-2270
RHSA-2011:0919
http://rhn.redhat.com/errata/RHSA-2011-0919.html
SUSE-SU-2011:0806
https://hermes.opensuse.org/messages/9605323
USN-1165-1
http://ubuntu.com/usn/usn-1165-1
[oss-security] 20110628 CVE request: qemu-kvm: OOB memory access caused by negative vq notifies
http://www.openwall.com/lists/oss-security/2011/06/28/13
[oss-security] 20110629 Re: CVE request: qemu-kvm: OOB memory access caused by negative vq notifies
http://www.openwall.com/lists/oss-security/2011/06/29/15
http://git.kernel.org/?p=virt/kvm/qemu-kvm.git%3Ba=commitdiff%3Bh=7157e2e23e89adcd436caeab31fdd6b47eded377
openSUSE-SU-2011:0803
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00007.html
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.