CVE-2014-3615)Xavier Mehrenberger and Stephane Duverger discovered that QEMU incorrectlyhandled certain udp packets when using guest networking. A malicious guestcould possibly use this issue to cause a denial of service. (CVE-2014-3640)It was discovered that QEMU incorrectly handled parameter validation inthe vmware_vga device. A malicious guest could possibly use this issue towrite into memory of the host, leading to privilege escalation.(CVE-2014-3689)It was discovered that QEMU incorrectly handled USB xHCI controller livemigration. An attacker could possibly use this issue to cause a denial ofservice, or possibly execute arbitrary code. This issue only affectedUbuntu 14.04 LTS. (CVE-2014-5263)Michael S. Tsirkin discovered that QEMU incorrectly handled memory in theACPI PCI hotplug interface. A malicious guest could possibly use this issueto access memory of the host, leading to information disclosure orprivilege escalation. This issue only affected Ubuntu 14.04 LTS.(CVE-2014-5388)James Spadaro discovered that QEMU incorrectly handled certain VNCbytes_per_pixel values. An attacker having access to a VNC console couldpossibly use this issue to cause a guest to crash, resulting in a denial ofservice. (CVE-2014-7815)"> OVAL Reference oval:org.mitre.oval:def:28286 - CERT Civis.Net
Oval Definition:oval:org.mitre.oval:def:28286
Revision Date:2015-03-09Version:5
Title:USN-2409-1 -- QEMU vulnerabilities
Description:Laszlo Ersek discovered that QEMU incorrectly handled memory in the vgadevice. A malicious guest could possibly use this issue to read arbitraryhost memory. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10.(CVE-2014-3615)Xavier Mehrenberger and Stephane Duverger discovered that QEMU incorrectlyhandled certain udp packets when using guest networking. A malicious guestcould possibly use this issue to cause a denial of service. (CVE-2014-3640)It was discovered that QEMU incorrectly handled parameter validation inthe vmware_vga device. A malicious guest could possibly use this issue towrite into memory of the host, leading to privilege escalation.(CVE-2014-3689)It was discovered that QEMU incorrectly handled USB xHCI controller livemigration. An attacker could possibly use this issue to cause a denial ofservice, or possibly execute arbitrary code. This issue only affectedUbuntu 14.04 LTS. (CVE-2014-5263)Michael S. Tsirkin discovered that QEMU incorrectly handled memory in theACPI PCI hotplug interface. A malicious guest could possibly use this issueto access memory of the host, leading to information disclosure orprivilege escalation. This issue only affected Ubuntu 14.04 LTS.(CVE-2014-5388)James Spadaro discovered that QEMU incorrectly handled certain VNCbytes_per_pixel values. An attacker having access to a VNC console couldpossibly use this issue to cause a guest to crash, resulting in a denial ofservice. (CVE-2014-7815)
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2014-3615
CVE-2014-3640
CVE-2014-3689
CVE-2014-5263
CVE-2014-5388
CVE-2014-7815
USN-2409-1
Platform(s):Ubuntu 10.04
Ubuntu 12.04
Ubuntu 14.04
Ubuntu 14.10
Product(s):qemu
qemu-kvm
Definition Synopsis
  • Ubuntu 14.10 release section
  • Ubuntu 14.10 is installed
  • AND Packages match section
  • qemu-system-misc is earlier than 0:2.1+dfsg-4ubuntu6.1
  • OR qemu-system is earlier than 0:2.1+dfsg-4ubuntu6.1
  • OR qemu-system-aarch64 is earlier than 0:2.1+dfsg-4ubuntu6.1
  • OR qemu-system-x86 is earlier than 0:2.1+dfsg-4ubuntu6.1
  • OR qemu-system-sparc is earlier than 0:2.1+dfsg-4ubuntu6.1
  • OR qemu-system-arm is earlier than 0:2.1+dfsg-4ubuntu6.1
  • OR qemu-system-ppc is earlier than 0:2.1+dfsg-4ubuntu6.1
  • OR qemu-system-mips is earlier than 0:2.1+dfsg-4ubuntu6.1
  • Ubuntu 14.04 release section
  • Ubuntu 14.04 is installed
  • AND Packages match section
  • qemu-system-misc is earlier than 0:2.0.0+dfsg-2ubuntu1.7
  • OR qemu-system is earlier than 0:2.0.0+dfsg-2ubuntu1.7
  • OR qemu-system-aarch64 is earlier than 0:2.0.0+dfsg-2ubuntu1.7
  • OR qemu-system-x86 is earlier than 0:2.0.0+dfsg-2ubuntu1.7
  • OR qemu-system-sparc is earlier than 0:2.0.0+dfsg-2ubuntu1.7
  • OR qemu-system-arm is earlier than 0:2.0.0+dfsg-2ubuntu1.7
  • OR qemu-system-ppc is earlier than 0:2.0.0+dfsg-2ubuntu1.7
  • OR qemu-system-mips is earlier than 0:2.0.0+dfsg-2ubuntu1.7
  • Ubuntu 12.04 release section
  • Ubuntu 12.04 is installed
  • AND qemu-kvm is earlier than 0:1.0+noroms-0ubuntu14.19
  • Ubuntu 10.04 release section
  • Ubuntu 10.04 is installed
  • AND qemu-kvm is earlier than 0:0.12.3+noroms-0ubuntu9.25
  • BACK