[GLSA-201804-08] QEMU: Multiple vulnerabilities

Severity Normal
Affected Packages 1
Unaffected Packages 1
CVEs 10

Multiple vulnerabilities have been found in QEMU, the worst of which may allow an attacker to execute arbitrary code.

Background
QEMU is a generic and open source machine emulator and virtualizer.

Description
Multiple vulnerabilities have been discovered in QEMU. Please review the
CVE identifiers referenced below for details.

Impact
An attacker could execute arbitrary code, cause a Denial of Service
condition, or obtain sensitive information.

Workaround
There is no known workaround at this time.

Resolution
All QEMU users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=app-emulation/qemu-2.11.1-r1"

Package Affected Version
pkg:ebuild/app-emulation/qemu?distro=gentoo < 2.11.1-r1
Package Unaffected Version
pkg:ebuild/app-emulation/qemu?distro=gentoo >= 2.11.1-r1
ID
GLSA-201804-08
Severity
normal
URL
https://security.gentoo.org/glsa/201804-08
Published
2018-04-08T00:00:00
(6 years ago)
Modified
2018-04-08T00:00:00
(6 years ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Source # ID Name URL
CVE CVE-2017-13672 CVE-2017-13672 https://nvd.nist.gov/vuln/detail/CVE-2017-13672
CVE CVE-2017-15124 CVE-2017-15124 https://nvd.nist.gov/vuln/detail/CVE-2017-15124
CVE CVE-2017-16845 CVE-2017-16845 https://nvd.nist.gov/vuln/detail/CVE-2017-16845
CVE CVE-2017-17381 CVE-2017-17381 https://nvd.nist.gov/vuln/detail/CVE-2017-17381
CVE CVE-2017-18030 CVE-2017-18030 https://nvd.nist.gov/vuln/detail/CVE-2017-18030
CVE CVE-2017-18043 CVE-2017-18043 https://nvd.nist.gov/vuln/detail/CVE-2017-18043
CVE CVE-2017-5715 CVE-2017-5715 https://nvd.nist.gov/vuln/detail/CVE-2017-5715
CVE CVE-2018-5683 CVE-2018-5683 https://nvd.nist.gov/vuln/detail/CVE-2018-5683
CVE CVE-2018-5748 CVE-2018-5748 https://nvd.nist.gov/vuln/detail/CVE-2018-5748
CVE CVE-2018-7550 CVE-2018-7550 https://nvd.nist.gov/vuln/detail/CVE-2018-7550
Bugzilla 629348 Bugzilla #629348 https://bugs.gentoo.org/show_bug.cgi?id=629348
Bugzilla 638506 Bugzilla #638506 https://bugs.gentoo.org/show_bug.cgi?id=638506
Bugzilla 643432 Bugzilla #643432 https://bugs.gentoo.org/show_bug.cgi?id=643432
Bugzilla 646814 Bugzilla #646814 https://bugs.gentoo.org/show_bug.cgi?id=646814
Bugzilla 649616 Bugzilla #649616 https://bugs.gentoo.org/show_bug.cgi?id=649616
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/app-emulation/qemu?distro=gentoo app-emulation qemu < 2.11.1-r1 gentoo
Unaffected pkg:ebuild/app-emulation/qemu?distro=gentoo app-emulation qemu >= 2.11.1-r1 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...