Oval Definition:oval:org.opensuse.security:def:55511
Revision Date:2020-12-01Version:1
Title:Security update for qemu (Important)
Description:



qemu / kvm was updated to fix a security issue and some bugs.

Security issue fixed:

CVE-2015-3456: Fixed a buffer overflow in the floppy drive emulation, which could be used to denial of service attacks or potential code execution against the host.

CVE-2015-1779: Fixed insufficient resource limiting in the VNC websockets decoder.



Bugs fixed: - qemu truncates vhd images in virt-rescue (bsc#886378)

- Update kvm-supported.txt with the current rbd support status.

- enable rbd build on x86_64 (qemu-block-rbd package) (FATE#318349)
Family:unixClass:patch
Status:Reference(s):1002998
1004490
1006368
1007249
1009961
1011348
1022062
1028744
1039513
1044016
1050947
1053431
1058425
1065237
1073748
1077559
1077568
1077572
1090671
1096209
1098155
1109847
1119183
1121816
1121821
1122191
1128712
1131709
1146569
1146571
1146572
1146702
755505
802639
821039
826906
855676
886378
895129
901902
906878
908362
908372
912014
912015
912018
912292
912293
912294
912296
924018
929339
967087
974208
978260
983015
987198
988274
988408
989566
995058
995102
995620
996015
999582
CVE-2009-2625
CVE-2009-3560
CVE-2009-3720
CVE-2010-0750
CVE-2010-5107
CVE-2011-1485
CVE-2012-0876
CVE-2012-1147
CVE-2012-1148
CVE-2013-4288
CVE-2014-3570
CVE-2014-3571
CVE-2014-3572
CVE-2014-8275
CVE-2015-0204
CVE-2015-0205
CVE-2015-0206
CVE-2015-1779
CVE-2015-3218
CVE-2015-3255
CVE-2015-3256
CVE-2015-3456
CVE-2015-4625
CVE-2016-1523
CVE-2016-7945
CVE-2016-7946
CVE-2016-8867
CVE-2017-10053
CVE-2017-10067
CVE-2017-10074
CVE-2017-10081
CVE-2017-10087
CVE-2017-10089
CVE-2017-10090
CVE-2017-10096
CVE-2017-10101
CVE-2017-10102
CVE-2017-10105
CVE-2017-10107
CVE-2017-10108
CVE-2017-10109
CVE-2017-10110
CVE-2017-10111
CVE-2017-10115
CVE-2017-10116
CVE-2017-10125
CVE-2017-10243
CVE-2017-11671
CVE-2017-14482
CVE-2018-1152
CVE-2018-11813
CVE-2018-14498
CVE-2018-14647
CVE-2018-6196
CVE-2018-6197
CVE-2018-6198
CVE-2019-15142
CVE-2019-15143
CVE-2019-15144
CVE-2019-15145
CVE-2019-5010
CVE-2019-6109
CVE-2019-6111
SUSE-SU-2015:0896-1
SUSE-SU-2016:0564-1
SUSE-SU-2016:3047-1
SUSE-SU-2016:3084-1
SUSE-SU-2017:2280-1
SUSE-SU-2017:2526-1
SUSE-SU-2017:2529-1
SUSE-SU-2019:0482-1
SUSE-SU-2019:0776-1
SUSE-SU-2019:1111-1
SUSE-SU-2019:1524-1
SUSE-SU-2019:2444-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Desktop 11 SP4
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP1
SUSE Linux Enterprise Server 12 SP1-LTSS
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • curl-7.59.0-lp150.1 is installed
  • OR libcurl4-7.59.0-lp150.1 is installed
  • OR libcurl4-32bit-7.59.0-lp150.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • GraphicsMagick-1.3.29-lp151.4.3 is installed
  • OR GraphicsMagick-devel-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagick++-Q16-12-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagick++-devel-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagick-Q16-3-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagick3-config-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagickWand-Q16-2-1.3.29-lp151.4.3 is installed
  • OR perl-GraphicsMagick-1.3.29-lp151.4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP2 is installed
  • AND Package Information
  • openssh-5.1p1-41.57 is installed
  • OR openssh-askpass-5.1p1-41.57 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • MozillaFirefox-38.6.1esr-34 is installed
  • OR MozillaFirefox-translations-38.6.1esr-34 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 is installed
  • AND Package Information
  • qemu-2.0.2-46 is installed
  • OR qemu-block-curl-2.0.2-46 is installed
  • OR qemu-ipxe-1.0.0-46 is installed
  • OR qemu-kvm-2.0.2-46 is installed
  • OR qemu-seabios-1.7.4-46 is installed
  • OR qemu-sgabios-8-46 is installed
  • OR qemu-tools-2.0.2-46 is installed
  • OR qemu-vgabios-1.7.4-46 is installed
  • OR qemu-x86-2.0.2-46 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP3 is installed
  • AND Package Information
  • libpython2_7-1_0-2.7.13-28.21 is installed
  • OR libpython2_7-1_0-32bit-2.7.13-28.21 is installed
  • OR python-2.7.13-28.21 is installed
  • OR python-base-2.7.13-28.21 is installed
  • OR python-curses-2.7.13-28.21 is installed
  • OR python-devel-2.7.13-28.21 is installed
  • OR python-tk-2.7.13-28.21 is installed
  • OR python-xml-2.7.13-28.21 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP4 is installed
  • AND Package Information
  • libjpeg-turbo-1.5.3-31.14 is installed
  • OR libjpeg62-62.2.0-31.14 is installed
  • OR libjpeg62-32bit-62.2.0-31.14 is installed
  • OR libjpeg62-turbo-1.5.3-31.14 is installed
  • OR libjpeg8-8.1.2-31.14 is installed
  • OR libjpeg8-32bit-8.1.2-31.14 is installed
  • OR libturbojpeg0-8.1.2-31.14 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1 is installed
  • AND Package Information
  • expat-2.1.0-13 is installed
  • OR libexpat1-2.1.0-13 is installed
  • OR libexpat1-32bit-2.1.0-13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP1-LTSS is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr4.10-38.5 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr4.10-38.5 is installed
  • OR java-1_7_1-ibm-devel-1.7.1_sr4.10-38.5 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr4.10-38.5 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr4.10-38.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2 is installed
  • AND Package Information
  • java-1_7_1-ibm-1.7.1_sr3.50-28 is installed
  • OR java-1_7_1-ibm-alsa-1.7.1_sr3.50-28 is installed
  • OR java-1_7_1-ibm-jdbc-1.7.1_sr3.50-28 is installed
  • OR java-1_7_1-ibm-plugin-1.7.1_sr3.50-28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND Package Information
  • libjavascriptcoregtk-4_0-18-2.28.2-2.53 is installed
  • OR libwebkit2gtk-4_0-37-2.28.2-2.53 is installed
  • OR libwebkit2gtk3-lang-2.28.2-2.53 is installed
  • OR typelib-1_0-JavaScriptCore-4_0-2.28.2-2.53 is installed
  • OR typelib-1_0-WebKit2-4_0-2.28.2-2.53 is installed
  • OR typelib-1_0-WebKit2WebExtension-4_0-2.28.2-2.53 is installed
  • OR webkit2gtk-4_0-injected-bundles-2.28.2-2.53 is installed
  • OR webkit2gtk3-2.28.2-2.53 is installed
  • OR webkit2gtk3-devel-2.28.2-2.53 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_121-92_95-default-7-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_25-7-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND Package Information
  • glibc-2.22-62.13 is installed
  • OR glibc-32bit-2.22-62.13 is installed
  • OR glibc-devel-2.22-62.13 is installed
  • OR glibc-devel-32bit-2.22-62.13 is installed
  • OR glibc-html-2.22-62.13 is installed
  • OR glibc-i18ndata-2.22-62.13 is installed
  • OR glibc-info-2.22-62.13 is installed
  • OR glibc-locale-2.22-62.13 is installed
  • OR glibc-locale-32bit-2.22-62.13 is installed
  • OR glibc-profile-2.22-62.13 is installed
  • OR glibc-profile-32bit-2.22-62.13 is installed
  • OR nscd-2.22-62.13 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • guestfs-data-1.32.4-19 is installed
  • OR guestfs-tools-1.32.4-19 is installed
  • OR guestfsd-1.32.4-19 is installed
  • OR libguestfs0-1.32.4-19 is installed
  • OR perl-Sys-Guestfs-1.32.4-19 is installed
  • OR python-libguestfs-1.32.4-19 is installed
  • OR virt-p2v-1.32.4-19 is installed
  • OR virt-v2v-1.32.4-19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • ghostscript-9.27-23.28 is installed
  • OR ghostscript-x11-9.27-23.28 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_155-94_50-default-7-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_17-7-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND shadow-4.2.1-27.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND chrony-2.3-3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND Package Information
  • containerd-0.2.4+gitr565_0366d7e-9 is installed
  • OR docker-1.12.3-81 is installed
  • OR runc-0.1.1+gitr2816_02f8fa7-9 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • openstack-magnum-3.1.2~a0~dev20-9 is installed
  • OR openstack-magnum-api-3.1.2~a0~dev20-9 is installed
  • OR openstack-magnum-conductor-3.1.2~a0~dev20-9 is installed
  • OR openstack-magnum-doc-3.1.2~a0~dev20-9 is installed
  • OR python-magnum-3.1.2~a0~dev20-9 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • galera-3-25.3.24-4.3 is installed
  • OR galera-3-wsrep-provider-25.3.24-4.3 is installed
  • OR libmariadb3-3.0.6-3.6 is installed
  • OR mariadb-10.2.21-4.8 is installed
  • OR mariadb-client-10.2.21-4.8 is installed
  • OR mariadb-connector-c-3.0.6-3.6 is installed
  • OR mariadb-errormessages-10.2.21-4.8 is installed
  • OR mariadb-galera-10.2.21-4.8 is installed
  • OR mariadb-tools-10.2.21-4.8 is installed
  • BACK