VYPR

rpm package

suse/qemu&distro=SUSE Linux Enterprise Server 12-LTSS

pkg:rpm/suse/qemu&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS

Vulnerabilities (98)

  • CVE-2017-7493HigMay 17, 2017
    affected < 2.0.2-48.34.3fixed 2.0.2-48.34.3

    Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to esca

  • CVE-2017-8112MedMay 2, 2017
    affected < 2.0.2-48.34.3fixed 2.0.2-48.34.3

    hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.

  • CVE-2017-8086MedMay 2, 2017
    affected < 2.0.2-48.34.3fixed 2.0.2-48.34.3

    Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable.

  • CVE-2017-7718MedApr 20, 2017
    affected < 2.0.2-48.34.3fixed 2.0.2-48.34.3

    hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functi

  • CVE-2017-7377MedApr 10, 2017
    affected < 2.0.2-48.34.3fixed 2.0.2-48.34.3

    The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.

  • CVE-2017-5973MedMar 27, 2017
    affected < 2.0.2-48.34.3fixed 2.0.2-48.34.3

    The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.

  • CVE-2016-9922MedMar 27, 2017
    affected < 2.0.2-48.31.1fixed 2.0.2-48.31.1

    The cirrus_do_copy function in hw/display/cirrus_vga.c in QEMU (aka Quick Emulator), when cirrus graphics mode is VGA, allows local guest OS privileged users to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving blit pitch values.

  • CVE-2017-5987MedMar 20, 2017
    affected < 2.0.2-48.34.3fixed 2.0.2-48.34.3

    The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving the transfer mode register during multi block transfer.

  • CVE-2017-5856MedMar 16, 2017
    affected < 2.0.2-48.31.1fixed 2.0.2-48.31.1

    Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over

  • CVE-2017-5667MedMar 16, 2017
    affected < 2.0.2-48.31.1fixed 2.0.2-48.31.1

    The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vectors involving the data transfer

  • CVE-2017-5898MedMar 15, 2017
    affected < 2.0.2-48.31.1fixed 2.0.2-48.31.1

    Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units

  • CVE-2017-5579MedMar 15, 2017
    affected < 2.0.2-48.34.3fixed 2.0.2-48.34.3

    Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.

  • CVE-2016-10155MedMar 15, 2017
    affected < 2.0.2-48.31.1fixed 2.0.2-48.31.1

    Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.

  • CVE-2017-6505MedMar 15, 2017
    affected < 2.0.2-48.34.3fixed 2.0.2-48.34.3

    The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) before 2.9.0 allows local guest OS users to cause a denial of service (infinite loop) via vectors involving the number of link endpoint list descriptors, a different vulnerability than CVE-2017-93

  • CVE-2016-9776MedDec 29, 2016
    affected < 2.0.2-48.31.1fixed 2.0.2-48.31.1

    QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this issue to crash the QEMU process

  • CVE-2016-9921MedDec 23, 2016
    affected < 2.0.2-48.31.1fixed 2.0.2-48.31.1

    Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process inst

  • CVE-2016-9911MedDec 23, 2016
    affected < 2.0.2-48.31.1fixed 2.0.2-48.31.1

    Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.

  • CVE-2016-9907MedDec 23, 2016
    affected < 2.0.2-48.31.1fixed 2.0.2-48.31.1

    Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a hos

  • CVE-2016-7421MedDec 10, 2016
    affected < 2.0.2-48.25.1fixed 2.0.2-48.25.1

    The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.

  • CVE-2016-7170MedDec 10, 2016
    affected < 2.0.2-48.25.1fixed 2.0.2-48.25.1

    The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[] array sizes when processing