VYPR

rpm package

almalinux/hivex

pkg:rpm/almalinux/hivex

Vulnerabilities (80)

  • CVE-2021-3592Jun 15, 2021
    affected < 1.3.18-21.module_el8.5.0+2608+72063365fixed 1.3.18-21.module_el8.5.0+2608+72063365

    An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this

  • CVE-2020-14301May 27, 2021
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configurat

  • CVE-2021-20196May 26, 2021
    affected < 1.3.18-23.module_el8.6.0+2880+7d9e3703fixed 1.3.18-23.module_el8.6.0+2880+7d9e3703

    A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commands if the selected floppy drive is not initialized with a block device. This flaw allows a privileged guest user to crash the QEMU process on

  • CVE-2020-35517Jan 28, 2021
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    A flaw was found in qemu. A host privilege escalation issue was found in the virtio-fs shared file system daemon where a privileged guest user is able to create a device special file in the shared directory and use it to r/w access host devices.

  • CVE-2020-29443Jan 22, 2021
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.

  • CVE-2020-11947Dec 31, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.

  • CVE-2020-27821Dec 8, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the

  • CVE-2020-28916Dec 4, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.

  • CVE-2020-14339Dec 3, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform ope

  • CVE-2020-25723Dec 2, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the

  • CVE-2020-29129Nov 26, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

  • CVE-2020-29130Nov 26, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

  • CVE-2020-25637Oct 6, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-w

  • CVE-2020-16092Aug 11, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw to abort the QEMU process on the host, resulting in a denial of service condition

  • CVE-2020-15859Jul 21, 2020
    affected < 1.3.18-21.module_el8.5.0+2608+72063365fixed 1.3.18-21.module_el8.5.0+2608+72063365

    QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.

  • CVE-2020-10756Jul 9, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of

  • CVE-2020-10703Jun 2, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in libvirt 6.0.0, for fetching a storage pool based on its target path. In more detail, this flaw affects storage pools created without a target path such as netwo

  • CVE-2020-1983Apr 22, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

  • CVE-2019-20485Mar 19, 2020
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

  • CVE-2019-15890Sep 6, 2019
    affected < 1.3.18-20.module_el8.3.0+2048+e7a0a3eafixed 1.3.18-20.module_el8.3.0+2048+e7a0a3ea

    libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.

Page 4 of 4