VYPR

rpm package

suse/libvirt&distro=SUSE Linux Enterprise Server for SAP Applications 11 SP4

pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4

Vulnerabilities (6)

  • CVE-2018-3639May 22, 2018
    affected < 1.2.5-23.15.1fixed 1.2.5-23.15.1

    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka

  • CVE-2018-1064Mar 28, 2018
    affected < 1.2.5-23.6.1fixed 1.2.5-23.6.1

    libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.

  • CVE-2018-5748Jan 25, 2018
    affected < 1.2.5-23.6.1fixed 1.2.5-23.6.1

    qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.

  • CVE-2017-5715Jan 4, 2018
    affected < 1.2.5-23.6.1fixed 1.2.5-23.6.1

    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

  • CVE-2016-5008CriJul 13, 2016
    affected < 1.2.5-15.3fixed 1.2.5-15.3

    libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

  • CVE-2015-5313LowApr 11, 2016
    affected < 1.2.5-12.3fixed 1.2.5-12.3

    Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write t