SB2018041304 - Red Hat update for qemu
Published: April 13, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Out-of-bounds read (CVE-ID: CVE-2017-13672)
The vulnerability allows an adjacent unauthenticated attacker to cause DoS condition on the target system.The weakness exists due to out-of-bounds read. An adjacent attacker can trigger memory corruption and cause the service to crash.
2) Improper input validation (CVE-ID: CVE-2017-13673)
The vulnerability allows an adjacent authenticated attacker to cause DoS condition on the target system.
The vulnerability exists in the vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode in the cpu_physical_memory_snapshot_get_dirty function due to assertion failure. An adjacent attacker can cause the service to crash.
3) Use-after-free error (CVE-ID: CVE-2017-13711)
The vulnerability allows an adjacent attacker to cause DoS condition on the target system.
The weakness exists in the Slirp networking implementation due to use-after-free error when a Socket referenced from multiple packets is freed while responding to a message. An adjacent attacker can cause the service to crash.
4) Resource exhaustion (CVE-ID: CVE-2017-15119)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to resource exhaustion when sending large option requests, making the server waste CPU time on reading up to 4GB per request. A remote attacker can cause the service to crash.
5) Memory allocation (CVE-ID: CVE-2017-15124)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to uncontrolled memory allocation when not throttling the framebuffer updates sent to the client. A remote attacker can cause the service to crash.
Remediation
Install update from vendor's website.