Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2014-5388 (GCVE-0-2014-5388)
Vulnerability from cvelistv5
Published
2014-11-15 21:00
Modified
2024-08-06 11:41
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.
References
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-06T11:41:49.221Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "name": "[Qemu-devel] 20140820 [PATCH v2] pcihp: fix possible array out of bounds", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html" }, { "name": "[oss-security] 20140822 CVE request Qemu: out of bounds memory access", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "http://seclists.org/oss-sec/2014/q3/438" }, { "name": "[oss-security] 20140822 Re: CVE request Qemu: out of bounds memory access", "tags": [ "mailing-list", "x_refsource_MLIST", "x_transferred" ], "url": "http://seclists.org/oss-sec/2014/q3/440" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1132956" }, { "name": "USN-2409-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU", "x_transferred" ], "url": "http://www.ubuntu.com/usn/USN-2409-1" }, { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "datePublic": "2014-08-20T00:00:00", "descriptions": [ { "lang": "en", "value": "Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2014-11-15T20:57:01", "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat" }, "references": [ { "name": "[Qemu-devel] 20140820 [PATCH v2] pcihp: fix possible array out of bounds", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html" }, { "name": "[oss-security] 20140822 CVE request Qemu: out of bounds memory access", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "http://seclists.org/oss-sec/2014/q3/438" }, { "name": "[oss-security] 20140822 Re: CVE request Qemu: out of bounds memory access", "tags": [ "mailing-list", "x_refsource_MLIST" ], "url": "http://seclists.org/oss-sec/2014/q3/440" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1132956" }, { "name": "USN-2409-1", "tags": [ "vendor-advisory", "x_refsource_UBUNTU" ], "url": "http://www.ubuntu.com/usn/USN-2409-1" }, { "tags": [ "x_refsource_CONFIRM" ], "url": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16" } ] } }, "cveMetadata": { "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "assignerShortName": "redhat", "cveId": "CVE-2014-5388", "datePublished": "2014-11-15T21:00:00", "dateReserved": "2014-08-22T00:00:00", "dateUpdated": "2024-08-06T11:41:49.221Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2014-5388\",\"sourceIdentifier\":\"secalert@redhat.com\",\"published\":\"2014-11-15T21:59:05.397\",\"lastModified\":\"2025-04-12T10:46:40.837\",\"vulnStatus\":\"Deferred\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.\"},{\"lang\":\"es\",\"value\":\"Error de superaci\u00f3n de l\u00edmite (off-by-one) en la funci\u00f3n pci_read en ACPI PCI interfaz hotplug (hw/acpi/pcihp.c) en QEMU permite a usuarios locales invitados obtener informaci\u00f3n sensible y tener otro impacto no especificado relacionado con un dispositivo PCI manipulado que provoca da\u00f1os en la memoria.\"}],\"metrics\":{\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:L/AC:L/Au:N/C:P/I:P/A:P\",\"baseScore\":4.6,\"accessVector\":\"LOCAL\",\"accessComplexity\":\"LOW\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"PARTIAL\",\"integrityImpact\":\"PARTIAL\",\"availabilityImpact\":\"PARTIAL\"},\"baseSeverity\":\"MEDIUM\",\"exploitabilityScore\":3.9,\"impactScore\":6.4,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-193\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*\",\"versionEndIncluding\":\"2.1.3\",\"matchCriteriaId\":\"3002CD11-CEF2-4CAF-A883-3B5BF4E8503A\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*\",\"matchCriteriaId\":\"01EDA41C-6B2E-49AF-B503-EB3882265C11\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*\",\"matchCriteriaId\":\"8D305F7A-D159-4716-AB26-5E38BB5CD991\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*\",\"matchCriteriaId\":\"815D70A8-47D3-459C-A32C-9FEACA0659D1\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"49A63F39-30BE-443F-AF10-6245587D3359\"}]}]}],\"references\":[{\"url\":\"http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://seclists.org/oss-sec/2014/q3/438\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Mailing List\",\"Patch\",\"Third Party Advisory\"]},{\"url\":\"http://seclists.org/oss-sec/2014/q3/440\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://www.ubuntu.com/usn/USN-2409-1\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1132956\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Issue Tracking\",\"Third Party Advisory\"]},{\"url\":\"https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Patch\",\"Third Party Advisory\"]},{\"url\":\"http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://seclists.org/oss-sec/2014/q3/438\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\",\"Patch\",\"Third Party Advisory\"]},{\"url\":\"http://seclists.org/oss-sec/2014/q3/440\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Mailing List\",\"Third Party Advisory\"]},{\"url\":\"http://www.ubuntu.com/usn/USN-2409-1\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=1132956\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Issue Tracking\",\"Third Party Advisory\"]},{\"url\":\"https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\",\"Third Party Advisory\"]}]}}" } }
gsd-2014-5388
Vulnerability from gsd
Modified
2023-12-13 01:22
Details
Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2014-5388", "description": "Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.", "id": "GSD-2014-5388", "references": [ "https://www.suse.com/security/cve/CVE-2014-5388.html", "https://ubuntu.com/security/CVE-2014-5388" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2014-5388" ], "details": "Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.", "id": "GSD-2014-5388", "modified": "2023-12-13T01:22:52.294157Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2014-5388", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_affected": "=", "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "http://www.ubuntu.com/usn/USN-2409-1", "refsource": "MISC", "url": "http://www.ubuntu.com/usn/USN-2409-1" }, { "name": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16", "refsource": "MISC", "url": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16" }, { "name": "http://seclists.org/oss-sec/2014/q3/438", "refsource": "MISC", "url": "http://seclists.org/oss-sec/2014/q3/438" }, { "name": "http://seclists.org/oss-sec/2014/q3/440", "refsource": "MISC", "url": "http://seclists.org/oss-sec/2014/q3/440" }, { "name": "https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html", "refsource": "MISC", "url": "https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html" }, { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1132956", "refsource": "MISC", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1132956" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndIncluding": "2.1.3", "vulnerable": true } ], "operator": "OR" }, { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*", "cpe_name": [], "vulnerable": true }, { "cpe23Uri": "cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "secalert@redhat.com", "ID": "CVE-2014-5388" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-193" } ] } ] }, "references": { "reference_data": [ { "name": "https://bugzilla.redhat.com/show_bug.cgi?id=1132956", "refsource": "CONFIRM", "tags": [ "Issue Tracking", "Third Party Advisory" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1132956" }, { "name": "[oss-security] 20140822 CVE request Qemu: out of bounds memory access", "refsource": "MLIST", "tags": [ "Mailing List", "Patch", "Third Party Advisory" ], "url": "http://seclists.org/oss-sec/2014/q3/438" }, { "name": "[oss-security] 20140822 Re: CVE request Qemu: out of bounds memory access", "refsource": "MLIST", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://seclists.org/oss-sec/2014/q3/440" }, { "name": "[Qemu-devel] 20140820 [PATCH v2] pcihp: fix possible array out of bounds", "refsource": "MLIST", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html" }, { "name": "USN-2409-1", "refsource": "UBUNTU", "tags": [ "Third Party Advisory" ], "url": "http://www.ubuntu.com/usn/USN-2409-1" }, { "name": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16", "refsource": "MISC", "tags": [], "url": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16" } ] } }, "impact": { "baseMetricV2": { "cvssV2": { "accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.6, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 3.9, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "MEDIUM", "userInteractionRequired": false } }, "lastModifiedDate": "2023-02-13T00:42Z", "publishedDate": "2014-11-15T21:59Z" } } }
suse-su-2016:2781-1
Vulnerability from csaf_suse
Published
2016-11-12 03:12
Modified
2016-11-12 03:12
Summary
Security update for qemu
Notes
Title of the patch
Security update for qemu
Description of the patch
qemu was updated to fix 21 security issues.
These security issues were fixed:
- CVE-2014-5388: Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allowed local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption (bsc#893323).
- CVE-2015-6815: e1000 NIC emulation support was vulnerable to an infinite loop issue. A privileged user inside guest could have used this flaw to crash the Qemu instance resulting in DoS. (bsc#944697).
- CVE-2016-2391: The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allowed local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers (bsc#967013).
- CVE-2016-2392: The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU did not properly validate USB configuration descriptor objects, which allowed local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet (bsc#967012).
- CVE-2016-4453: The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allowed local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command (bsc#982223).
- CVE-2016-4454: The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allowed local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read (bsc#982222).
- CVE-2016-5105: The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, used an uninitialized variable, which allowed local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command (bsc#982017).
- CVE-2016-5106: The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allowed local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command (bsc#982018).
- CVE-2016-5107: The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allowed local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors (bsc#982019).
- CVE-2016-5126: Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allowed local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call (bsc#982285).
- CVE-2016-5238: The get_cmd function in hw/scsi/esp.c in QEMU allowed local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode (bsc#982959).
- CVE-2016-5337: The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allowed local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information (bsc#983961).
- CVE-2016-5338: The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allowed local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer (bsc#983982).
- CVE-2016-5403: The virtqueue_pop function in hw/virtio/virtio.c in QEMU allowed local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion (bsc#991080).
- CVE-2016-6490: Infinite loop in the virtio framework. A privileged user inside the guest could have used this flaw to crash the Qemu instance on the host resulting in DoS (bsc#991466).
- CVE-2016-6833: Use-after-free issue in the VMWARE VMXNET3 NIC device support. A privileged user inside guest could have used this issue to crash the Qemu instance resulting in DoS (bsc#994774).
- CVE-2016-6836: VMWARE VMXNET3 NIC device support was leaging information leakage. A privileged user inside guest could have used this to leak host memory bytes to a guest (bsc#994760).
- CVE-2016-6888: Integer overflow in packet initialisation in VMXNET3 device driver. A privileged user inside guest could have used this flaw to crash the Qemu instance resulting in DoS (bsc#994771).
- CVE-2016-7116: Host directory sharing via Plan 9 File System(9pfs) was vulnerable to a directory/path traversal issue. A privileged user inside guest could have used this flaw to access undue files on the host (bsc#996441).
- CVE-2016-7155: In the VMWARE PVSCSI paravirtual SCSI bus a OOB access and/or infinite loop issue could have allowed a privileged user inside guest to crash the Qemu process resulting in DoS (bsc#997858).
- CVE-2016-7156: In the VMWARE PVSCSI paravirtual SCSI bus a infinite loop issue could have allowed a privileged user inside guest to crash the Qemu process resulting in DoS (bsc#997859).
Patchnames
SUSE-SLE-SAP-12-2016-1646,SUSE-SLE-SERVER-12-2016-1646
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for qemu", "title": "Title of the patch" }, { "category": "description", "text": "qemu was updated to fix 21 security issues.\n\nThese security issues were fixed:\n- CVE-2014-5388: Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allowed local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption (bsc#893323).\n- CVE-2015-6815: e1000 NIC emulation support was vulnerable to an infinite loop issue. A privileged user inside guest could have used this flaw to crash the Qemu instance resulting in DoS. (bsc#944697).\n- CVE-2016-2391: The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allowed local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers (bsc#967013).\n- CVE-2016-2392: The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU did not properly validate USB configuration descriptor objects, which allowed local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet (bsc#967012).\n- CVE-2016-4453: The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allowed local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command (bsc#982223).\n- CVE-2016-4454: The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allowed local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read (bsc#982222).\n- CVE-2016-5105: The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, used an uninitialized variable, which allowed local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command (bsc#982017).\n- CVE-2016-5106: The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allowed local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command (bsc#982018).\n- CVE-2016-5107: The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allowed local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors (bsc#982019).\n- CVE-2016-5126: Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allowed local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call (bsc#982285).\n- CVE-2016-5238: The get_cmd function in hw/scsi/esp.c in QEMU allowed local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode (bsc#982959).\n- CVE-2016-5337: The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allowed local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information (bsc#983961).\n- CVE-2016-5338: The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allowed local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer (bsc#983982).\n- CVE-2016-5403: The virtqueue_pop function in hw/virtio/virtio.c in QEMU allowed local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion (bsc#991080).\n- CVE-2016-6490: Infinite loop in the virtio framework. A privileged user inside the guest could have used this flaw to crash the Qemu instance on the host resulting in DoS (bsc#991466).\n- CVE-2016-6833: Use-after-free issue in the VMWARE VMXNET3 NIC device support. A privileged user inside guest could have used this issue to crash the Qemu instance resulting in DoS (bsc#994774).\n- CVE-2016-6836: VMWARE VMXNET3 NIC device support was leaging information leakage. A privileged user inside guest could have used this to leak host memory bytes to a guest (bsc#994760).\n- CVE-2016-6888: Integer overflow in packet initialisation in VMXNET3 device driver. A privileged user inside guest could have used this flaw to crash the Qemu instance resulting in DoS (bsc#994771).\n- CVE-2016-7116: Host directory sharing via Plan 9 File System(9pfs) was vulnerable to a directory/path traversal issue. A privileged user inside guest could have used this flaw to access undue files on the host (bsc#996441).\n- CVE-2016-7155: In the VMWARE PVSCSI paravirtual SCSI bus a OOB access and/or infinite loop issue could have allowed a privileged user inside guest to crash the Qemu process resulting in DoS (bsc#997858).\n- CVE-2016-7156: In the VMWARE PVSCSI paravirtual SCSI bus a infinite loop issue could have allowed a privileged user inside guest to crash the Qemu process resulting in DoS (bsc#997859).\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-SLE-SAP-12-2016-1646,SUSE-SLE-SERVER-12-2016-1646", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2016_2781-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2016:2781-1", "url": "https://www.suse.com/support/update/announcement/2016/suse-su-20162781-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2016:2781-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2016-November/002402.html" }, { "category": "self", "summary": "SUSE Bug 893323", "url": "https://bugzilla.suse.com/893323" }, { "category": "self", "summary": "SUSE Bug 944697", "url": "https://bugzilla.suse.com/944697" }, { "category": "self", "summary": "SUSE Bug 967012", "url": "https://bugzilla.suse.com/967012" }, { "category": "self", "summary": "SUSE Bug 967013", "url": "https://bugzilla.suse.com/967013" }, { "category": "self", "summary": "SUSE Bug 982017", "url": "https://bugzilla.suse.com/982017" }, { "category": "self", "summary": "SUSE Bug 982018", "url": "https://bugzilla.suse.com/982018" }, { "category": "self", "summary": "SUSE Bug 982019", "url": "https://bugzilla.suse.com/982019" }, { "category": "self", "summary": "SUSE Bug 982222", "url": "https://bugzilla.suse.com/982222" }, { "category": "self", "summary": "SUSE Bug 982223", "url": "https://bugzilla.suse.com/982223" }, { "category": "self", "summary": "SUSE Bug 982285", "url": "https://bugzilla.suse.com/982285" }, { "category": "self", "summary": "SUSE Bug 982959", "url": "https://bugzilla.suse.com/982959" }, { "category": "self", "summary": "SUSE Bug 983961", "url": "https://bugzilla.suse.com/983961" }, { "category": "self", "summary": "SUSE Bug 983982", "url": "https://bugzilla.suse.com/983982" }, { "category": "self", "summary": "SUSE Bug 991080", "url": "https://bugzilla.suse.com/991080" }, { "category": "self", "summary": "SUSE Bug 991466", "url": "https://bugzilla.suse.com/991466" }, { "category": "self", "summary": "SUSE Bug 994760", "url": "https://bugzilla.suse.com/994760" }, { "category": "self", "summary": "SUSE Bug 994771", "url": "https://bugzilla.suse.com/994771" }, { "category": "self", "summary": "SUSE Bug 994774", "url": "https://bugzilla.suse.com/994774" }, { "category": "self", "summary": "SUSE Bug 996441", "url": "https://bugzilla.suse.com/996441" }, { "category": "self", "summary": "SUSE Bug 997858", "url": "https://bugzilla.suse.com/997858" }, { "category": "self", "summary": "SUSE Bug 997859", "url": "https://bugzilla.suse.com/997859" }, { "category": "self", "summary": "SUSE CVE CVE-2014-5388 page", "url": "https://www.suse.com/security/cve/CVE-2014-5388/" }, { "category": "self", "summary": "SUSE CVE CVE-2015-6815 page", "url": "https://www.suse.com/security/cve/CVE-2015-6815/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2391 page", "url": "https://www.suse.com/security/cve/CVE-2016-2391/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2392 page", "url": "https://www.suse.com/security/cve/CVE-2016-2392/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-4453 page", "url": "https://www.suse.com/security/cve/CVE-2016-4453/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-4454 page", "url": "https://www.suse.com/security/cve/CVE-2016-4454/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-5105 page", "url": "https://www.suse.com/security/cve/CVE-2016-5105/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-5106 page", "url": "https://www.suse.com/security/cve/CVE-2016-5106/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-5107 page", "url": "https://www.suse.com/security/cve/CVE-2016-5107/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-5126 page", "url": "https://www.suse.com/security/cve/CVE-2016-5126/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-5238 page", "url": "https://www.suse.com/security/cve/CVE-2016-5238/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-5337 page", "url": "https://www.suse.com/security/cve/CVE-2016-5337/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-5338 page", "url": "https://www.suse.com/security/cve/CVE-2016-5338/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-5403 page", "url": "https://www.suse.com/security/cve/CVE-2016-5403/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-6490 page", "url": "https://www.suse.com/security/cve/CVE-2016-6490/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-6833 page", "url": "https://www.suse.com/security/cve/CVE-2016-6833/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-6836 page", "url": "https://www.suse.com/security/cve/CVE-2016-6836/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-6888 page", "url": "https://www.suse.com/security/cve/CVE-2016-6888/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7116 page", "url": "https://www.suse.com/security/cve/CVE-2016-7116/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7155 page", "url": "https://www.suse.com/security/cve/CVE-2016-7155/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7156 page", "url": "https://www.suse.com/security/cve/CVE-2016-7156/" } ], "title": "Security update for qemu", "tracking": { "current_release_date": "2016-11-12T03:12:32Z", "generator": { "date": "2016-11-12T03:12:32Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2016:2781-1", "initial_release_date": "2016-11-12T03:12:32Z", "revision_history": [ { "date": "2016-11-12T03:12:32Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "qemu-ipxe-1.0.0-48.22.1.noarch", "product": { "name": "qemu-ipxe-1.0.0-48.22.1.noarch", "product_id": "qemu-ipxe-1.0.0-48.22.1.noarch" } }, { "category": "product_version", "name": "qemu-seabios-1.7.4-48.22.1.noarch", "product": { "name": "qemu-seabios-1.7.4-48.22.1.noarch", "product_id": "qemu-seabios-1.7.4-48.22.1.noarch" } }, { "category": "product_version", "name": "qemu-sgabios-8-48.22.1.noarch", "product": { "name": "qemu-sgabios-8-48.22.1.noarch", "product_id": "qemu-sgabios-8-48.22.1.noarch" } }, { "category": "product_version", "name": "qemu-vgabios-1.7.4-48.22.1.noarch", "product": { "name": "qemu-vgabios-1.7.4-48.22.1.noarch", "product_id": "qemu-vgabios-1.7.4-48.22.1.noarch" } } ], "category": "architecture", "name": "noarch" }, { "branches": [ { "category": "product_version", "name": "qemu-2.0.2-48.22.1.ppc64le", "product": { "name": "qemu-2.0.2-48.22.1.ppc64le", "product_id": "qemu-2.0.2-48.22.1.ppc64le" } }, { "category": "product_version", "name": "qemu-block-curl-2.0.2-48.22.1.ppc64le", "product": { "name": "qemu-block-curl-2.0.2-48.22.1.ppc64le", "product_id": "qemu-block-curl-2.0.2-48.22.1.ppc64le" } }, { "category": "product_version", "name": "qemu-guest-agent-2.0.2-48.22.1.ppc64le", "product": { "name": "qemu-guest-agent-2.0.2-48.22.1.ppc64le", "product_id": "qemu-guest-agent-2.0.2-48.22.1.ppc64le" } }, { "category": "product_version", "name": "qemu-lang-2.0.2-48.22.1.ppc64le", "product": { "name": "qemu-lang-2.0.2-48.22.1.ppc64le", "product_id": "qemu-lang-2.0.2-48.22.1.ppc64le" } }, { "category": "product_version", "name": "qemu-ppc-2.0.2-48.22.1.ppc64le", "product": { "name": "qemu-ppc-2.0.2-48.22.1.ppc64le", "product_id": "qemu-ppc-2.0.2-48.22.1.ppc64le" } }, { "category": "product_version", "name": "qemu-tools-2.0.2-48.22.1.ppc64le", "product": { "name": "qemu-tools-2.0.2-48.22.1.ppc64le", "product_id": "qemu-tools-2.0.2-48.22.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "qemu-2.0.2-48.22.1.s390x", "product": { "name": "qemu-2.0.2-48.22.1.s390x", "product_id": "qemu-2.0.2-48.22.1.s390x" } }, { "category": "product_version", "name": "qemu-block-curl-2.0.2-48.22.1.s390x", "product": { "name": "qemu-block-curl-2.0.2-48.22.1.s390x", "product_id": "qemu-block-curl-2.0.2-48.22.1.s390x" } }, { "category": "product_version", "name": "qemu-guest-agent-2.0.2-48.22.1.s390x", "product": { "name": "qemu-guest-agent-2.0.2-48.22.1.s390x", "product_id": "qemu-guest-agent-2.0.2-48.22.1.s390x" } }, { "category": "product_version", "name": "qemu-kvm-2.0.2-48.22.1.s390x", "product": { "name": "qemu-kvm-2.0.2-48.22.1.s390x", "product_id": "qemu-kvm-2.0.2-48.22.1.s390x" } }, { "category": "product_version", "name": "qemu-lang-2.0.2-48.22.1.s390x", "product": { "name": "qemu-lang-2.0.2-48.22.1.s390x", "product_id": "qemu-lang-2.0.2-48.22.1.s390x" } }, { "category": "product_version", "name": "qemu-s390-2.0.2-48.22.1.s390x", "product": { "name": "qemu-s390-2.0.2-48.22.1.s390x", "product_id": "qemu-s390-2.0.2-48.22.1.s390x" } }, { "category": "product_version", "name": "qemu-tools-2.0.2-48.22.1.s390x", "product": { "name": "qemu-tools-2.0.2-48.22.1.s390x", "product_id": "qemu-tools-2.0.2-48.22.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "qemu-2.0.2-48.22.1.x86_64", "product": { "name": "qemu-2.0.2-48.22.1.x86_64", "product_id": "qemu-2.0.2-48.22.1.x86_64" } }, { "category": "product_version", "name": "qemu-block-curl-2.0.2-48.22.1.x86_64", "product": { "name": "qemu-block-curl-2.0.2-48.22.1.x86_64", "product_id": "qemu-block-curl-2.0.2-48.22.1.x86_64" } }, { "category": "product_version", "name": "qemu-block-rbd-2.0.2-48.22.1.x86_64", "product": { "name": "qemu-block-rbd-2.0.2-48.22.1.x86_64", "product_id": "qemu-block-rbd-2.0.2-48.22.1.x86_64" } }, { "category": "product_version", "name": "qemu-guest-agent-2.0.2-48.22.1.x86_64", "product": { "name": "qemu-guest-agent-2.0.2-48.22.1.x86_64", "product_id": "qemu-guest-agent-2.0.2-48.22.1.x86_64" } }, { "category": "product_version", "name": "qemu-kvm-2.0.2-48.22.1.x86_64", "product": { "name": "qemu-kvm-2.0.2-48.22.1.x86_64", "product_id": "qemu-kvm-2.0.2-48.22.1.x86_64" } }, { "category": "product_version", "name": "qemu-lang-2.0.2-48.22.1.x86_64", "product": { "name": "qemu-lang-2.0.2-48.22.1.x86_64", "product_id": "qemu-lang-2.0.2-48.22.1.x86_64" } }, { "category": "product_version", "name": "qemu-tools-2.0.2-48.22.1.x86_64", "product": { "name": "qemu-tools-2.0.2-48.22.1.x86_64", "product_id": "qemu-tools-2.0.2-48.22.1.x86_64" } }, { "category": "product_version", "name": "qemu-x86-2.0.2-48.22.1.x86_64", "product": { "name": "qemu-x86-2.0.2-48.22.1.x86_64", "product_id": "qemu-x86-2.0.2-48.22.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux Enterprise Server for SAP Applications 12", "product": { "name": "SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12", "product_identification_helper": { "cpe": "cpe:/o:suse:sles_sap:12" } } }, { "category": "product_name", "name": "SUSE Linux Enterprise Server 12-LTSS", "product": { "name": "SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS", "product_identification_helper": { "cpe": "cpe:/o:suse:sles-ltss:12" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "qemu-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-curl-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-block-curl-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-rbd-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-block-rbd-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-guest-agent-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-guest-agent-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-ipxe-1.0.0-48.22.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch" }, "product_reference": "qemu-ipxe-1.0.0-48.22.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-kvm-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-kvm-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-lang-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-lang-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-seabios-1.7.4-48.22.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch" }, "product_reference": "qemu-seabios-1.7.4-48.22.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-sgabios-8-48.22.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch" }, "product_reference": "qemu-sgabios-8-48.22.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-tools-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-tools-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-vgabios-1.7.4-48.22.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch" }, "product_reference": "qemu-vgabios-1.7.4-48.22.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-x86-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-x86-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-2.0.2-48.22.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le" }, "product_reference": "qemu-2.0.2-48.22.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-2.0.2-48.22.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x" }, "product_reference": "qemu-2.0.2-48.22.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-curl-2.0.2-48.22.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le" }, "product_reference": "qemu-block-curl-2.0.2-48.22.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-curl-2.0.2-48.22.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x" }, "product_reference": "qemu-block-curl-2.0.2-48.22.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-curl-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-block-curl-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-rbd-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-block-rbd-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-guest-agent-2.0.2-48.22.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le" }, "product_reference": "qemu-guest-agent-2.0.2-48.22.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-guest-agent-2.0.2-48.22.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x" }, "product_reference": "qemu-guest-agent-2.0.2-48.22.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-guest-agent-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-guest-agent-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-ipxe-1.0.0-48.22.1.noarch as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch" }, "product_reference": "qemu-ipxe-1.0.0-48.22.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-kvm-2.0.2-48.22.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x" }, "product_reference": "qemu-kvm-2.0.2-48.22.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-kvm-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-kvm-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-lang-2.0.2-48.22.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le" }, "product_reference": "qemu-lang-2.0.2-48.22.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-lang-2.0.2-48.22.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x" }, "product_reference": "qemu-lang-2.0.2-48.22.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-lang-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-lang-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-ppc-2.0.2-48.22.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le" }, "product_reference": "qemu-ppc-2.0.2-48.22.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-s390-2.0.2-48.22.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x" }, "product_reference": "qemu-s390-2.0.2-48.22.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-seabios-1.7.4-48.22.1.noarch as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch" }, "product_reference": "qemu-seabios-1.7.4-48.22.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-sgabios-8-48.22.1.noarch as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch" }, "product_reference": "qemu-sgabios-8-48.22.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-tools-2.0.2-48.22.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le" }, "product_reference": "qemu-tools-2.0.2-48.22.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-tools-2.0.2-48.22.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x" }, "product_reference": "qemu-tools-2.0.2-48.22.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-tools-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-tools-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-vgabios-1.7.4-48.22.1.noarch as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch" }, "product_reference": "qemu-vgabios-1.7.4-48.22.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-x86-2.0.2-48.22.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64" }, "product_reference": "qemu-x86-2.0.2-48.22.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" } ] }, "vulnerabilities": [ { "cve": "CVE-2014-5388", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2014-5388" } ], "notes": [ { "category": "general", "text": "Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2014-5388", "url": "https://www.suse.com/security/cve/CVE-2014-5388" }, { "category": "external", "summary": "SUSE Bug 893323 for CVE-2014-5388", "url": "https://bugzilla.suse.com/893323" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "moderate" } ], "title": "CVE-2014-5388" }, { "cve": "CVE-2015-6815", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2015-6815" } ], "notes": [ { "category": "general", "text": "The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2015-6815", "url": "https://www.suse.com/security/cve/CVE-2015-6815" }, { "category": "external", "summary": "SUSE Bug 944697 for CVE-2015-6815", "url": "https://bugzilla.suse.com/944697" }, { "category": "external", "summary": "SUSE Bug 950367 for CVE-2015-6815", "url": "https://bugzilla.suse.com/950367" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.5, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2015-6815" }, { "cve": "CVE-2016-2391", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2391" } ], "notes": [ { "category": "general", "text": "The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2391", "url": "https://www.suse.com/security/cve/CVE-2016-2391" }, { "category": "external", "summary": "SUSE Bug 967012 for CVE-2016-2391", "url": "https://bugzilla.suse.com/967012" }, { "category": "external", "summary": "SUSE Bug 967013 for CVE-2016-2391", "url": "https://bugzilla.suse.com/967013" }, { "category": "external", "summary": "SUSE Bug 967101 for CVE-2016-2391", "url": "https://bugzilla.suse.com/967101" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-2391" }, { "cve": "CVE-2016-2392", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2392" } ], "notes": [ { "category": "general", "text": "The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2392", "url": "https://www.suse.com/security/cve/CVE-2016-2392" }, { "category": "external", "summary": "SUSE Bug 967012 for CVE-2016-2392", "url": "https://bugzilla.suse.com/967012" }, { "category": "external", "summary": "SUSE Bug 967090 for CVE-2016-2392", "url": "https://bugzilla.suse.com/967090" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-2392" }, { "cve": "CVE-2016-4453", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-4453" } ], "notes": [ { "category": "general", "text": "The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-4453", "url": "https://www.suse.com/security/cve/CVE-2016-4453" }, { "category": "external", "summary": "SUSE Bug 982223 for CVE-2016-4453", "url": "https://bugzilla.suse.com/982223" }, { "category": "external", "summary": "SUSE Bug 982225 for CVE-2016-4453", "url": "https://bugzilla.suse.com/982225" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-4453" }, { "cve": "CVE-2016-4454", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-4454" } ], "notes": [ { "category": "general", "text": "The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-4454", "url": "https://www.suse.com/security/cve/CVE-2016-4454" }, { "category": "external", "summary": "SUSE Bug 982222 for CVE-2016-4454", "url": "https://bugzilla.suse.com/982222" }, { "category": "external", "summary": "SUSE Bug 982224 for CVE-2016-4454", "url": "https://bugzilla.suse.com/982224" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-4454" }, { "cve": "CVE-2016-5105", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-5105" } ], "notes": [ { "category": "general", "text": "The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-5105", "url": "https://www.suse.com/security/cve/CVE-2016-5105" }, { "category": "external", "summary": "SUSE Bug 982017 for CVE-2016-5105", "url": "https://bugzilla.suse.com/982017" }, { "category": "external", "summary": "SUSE Bug 982024 for CVE-2016-5105", "url": "https://bugzilla.suse.com/982024" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-5105" }, { "cve": "CVE-2016-5106", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-5106" } ], "notes": [ { "category": "general", "text": "The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-5106", "url": "https://www.suse.com/security/cve/CVE-2016-5106" }, { "category": "external", "summary": "SUSE Bug 982018 for CVE-2016-5106", "url": "https://bugzilla.suse.com/982018" }, { "category": "external", "summary": "SUSE Bug 982025 for CVE-2016-5106", "url": "https://bugzilla.suse.com/982025" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-5106" }, { "cve": "CVE-2016-5107", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-5107" } ], "notes": [ { "category": "general", "text": "The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-5107", "url": "https://www.suse.com/security/cve/CVE-2016-5107" }, { "category": "external", "summary": "SUSE Bug 982019 for CVE-2016-5107", "url": "https://bugzilla.suse.com/982019" }, { "category": "external", "summary": "SUSE Bug 982026 for CVE-2016-5107", "url": "https://bugzilla.suse.com/982026" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-5107" }, { "cve": "CVE-2016-5126", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-5126" } ], "notes": [ { "category": "general", "text": "Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-5126", "url": "https://www.suse.com/security/cve/CVE-2016-5126" }, { "category": "external", "summary": "SUSE Bug 982285 for CVE-2016-5126", "url": "https://bugzilla.suse.com/982285" }, { "category": "external", "summary": "SUSE Bug 982286 for CVE-2016-5126", "url": "https://bugzilla.suse.com/982286" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-5126" }, { "cve": "CVE-2016-5238", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-5238" } ], "notes": [ { "category": "general", "text": "The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-5238", "url": "https://www.suse.com/security/cve/CVE-2016-5238" }, { "category": "external", "summary": "SUSE Bug 982959 for CVE-2016-5238", "url": "https://bugzilla.suse.com/982959" }, { "category": "external", "summary": "SUSE Bug 982960 for CVE-2016-5238", "url": "https://bugzilla.suse.com/982960" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "moderate" } ], "title": "CVE-2016-5238" }, { "cve": "CVE-2016-5337", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-5337" } ], "notes": [ { "category": "general", "text": "The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-5337", "url": "https://www.suse.com/security/cve/CVE-2016-5337" }, { "category": "external", "summary": "SUSE Bug 983961 for CVE-2016-5337", "url": "https://bugzilla.suse.com/983961" }, { "category": "external", "summary": "SUSE Bug 983973 for CVE-2016-5337", "url": "https://bugzilla.suse.com/983973" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-5337" }, { "cve": "CVE-2016-5338", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-5338" } ], "notes": [ { "category": "general", "text": "The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-5338", "url": "https://www.suse.com/security/cve/CVE-2016-5338" }, { "category": "external", "summary": "SUSE Bug 983982 for CVE-2016-5338", "url": "https://bugzilla.suse.com/983982" }, { "category": "external", "summary": "SUSE Bug 983984 for CVE-2016-5338", "url": "https://bugzilla.suse.com/983984" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-5338" }, { "cve": "CVE-2016-5403", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-5403" } ], "notes": [ { "category": "general", "text": "The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-5403", "url": "https://www.suse.com/security/cve/CVE-2016-5403" }, { "category": "external", "summary": "SUSE Bug 990923 for CVE-2016-5403", "url": "https://bugzilla.suse.com/990923" }, { "category": "external", "summary": "SUSE Bug 991080 for CVE-2016-5403", "url": "https://bugzilla.suse.com/991080" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-5403" }, { "cve": "CVE-2016-6490", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-6490" } ], "notes": [ { "category": "general", "text": "The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the descriptor buffer.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-6490", "url": "https://www.suse.com/security/cve/CVE-2016-6490" }, { "category": "external", "summary": "SUSE Bug 991466 for CVE-2016-6490", "url": "https://bugzilla.suse.com/991466" }, { "category": "external", "summary": "SUSE Bug 993854 for CVE-2016-6490", "url": "https://bugzilla.suse.com/993854" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-6490" }, { "cve": "CVE-2016-6833", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-6833" } ], "notes": [ { "category": "general", "text": "Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging failure to check if the device is active.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-6833", "url": "https://www.suse.com/security/cve/CVE-2016-6833" }, { "category": "external", "summary": "SUSE Bug 994774 for CVE-2016-6833", "url": "https://bugzilla.suse.com/994774" }, { "category": "external", "summary": "SUSE Bug 994775 for CVE-2016-6833", "url": "https://bugzilla.suse.com/994775" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "moderate" } ], "title": "CVE-2016-6833" }, { "cve": "CVE-2016-6836", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-6836" } ], "notes": [ { "category": "general", "text": "The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveraging failure to initialize the txcq_descr object.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-6836", "url": "https://www.suse.com/security/cve/CVE-2016-6836" }, { "category": "external", "summary": "SUSE Bug 994760 for CVE-2016-6836", "url": "https://bugzilla.suse.com/994760" }, { "category": "external", "summary": "SUSE Bug 994761 for CVE-2016-6836", "url": "https://bugzilla.suse.com/994761" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-6836" }, { "cve": "CVE-2016-6888", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-6888" } ], "notes": [ { "category": "general", "text": "Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-6888", "url": "https://www.suse.com/security/cve/CVE-2016-6888" }, { "category": "external", "summary": "SUSE Bug 994771 for CVE-2016-6888", "url": "https://bugzilla.suse.com/994771" }, { "category": "external", "summary": "SUSE Bug 994772 for CVE-2016-6888", "url": "https://bugzilla.suse.com/994772" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-6888" }, { "cve": "CVE-2016-7116", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7116" } ], "notes": [ { "category": "general", "text": "Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7116", "url": "https://www.suse.com/security/cve/CVE-2016-7116" }, { "category": "external", "summary": "SUSE Bug 996441 for CVE-2016-7116", "url": "https://bugzilla.suse.com/996441" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "low" } ], "title": "CVE-2016-7116" }, { "cve": "CVE-2016-7155", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7155" } ], "notes": [ { "category": "general", "text": "hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7155", "url": "https://www.suse.com/security/cve/CVE-2016-7155" }, { "category": "external", "summary": "SUSE Bug 997858 for CVE-2016-7155", "url": "https://bugzilla.suse.com/997858" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "moderate" } ], "title": "CVE-2016-7155" }, { "cve": "CVE-2016-7156", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7156" } ], "notes": [ { "category": "general", "text": "The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect cast.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7156", "url": "https://www.suse.com/security/cve/CVE-2016-7156" }, { "category": "external", "summary": "SUSE Bug 997859 for CVE-2016-7156", "url": "https://bugzilla.suse.com/997859" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.22.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.22.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.22.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-12T03:12:32Z", "details": "moderate" } ], "title": "CVE-2016-7156" } ] }
ghsa-hxhj-7442-hjrx
Vulnerability from github
Published
2022-05-13 01:23
Modified
2022-05-13 01:23
VLAI Severity ?
Details
Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.
{ "affected": [], "aliases": [ "CVE-2014-5388" ], "database_specific": { "cwe_ids": [ "CWE-193" ], "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2014-11-15T21:59:00Z", "severity": "MODERATE" }, "details": "Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.", "id": "GHSA-hxhj-7442-hjrx", "modified": "2022-05-13T01:23:54Z", "published": "2022-05-13T01:23:54Z", "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-5388" }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1132956" }, { "type": "WEB", "url": "https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html" }, { "type": "WEB", "url": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16" }, { "type": "WEB", "url": "http://git.qemu.org/?p=qemu.git;a=commit;h=fa365d7cd11185237471823a5a33d36765454e16" }, { "type": "WEB", "url": "http://seclists.org/oss-sec/2014/q3/438" }, { "type": "WEB", "url": "http://seclists.org/oss-sec/2014/q3/440" }, { "type": "WEB", "url": "http://www.ubuntu.com/usn/USN-2409-1" } ], "schema_version": "1.4.0", "severity": [] }
fkie_cve-2014-5388
Vulnerability from fkie_nvd
Published
2014-11-15 21:59
Modified
2025-04-12 10:46
Severity ?
Summary
Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.
References
▶ | URL | Tags | |
---|---|---|---|
secalert@redhat.com | http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16 | ||
secalert@redhat.com | http://seclists.org/oss-sec/2014/q3/438 | Mailing List, Patch, Third Party Advisory | |
secalert@redhat.com | http://seclists.org/oss-sec/2014/q3/440 | Mailing List, Third Party Advisory | |
secalert@redhat.com | http://www.ubuntu.com/usn/USN-2409-1 | Third Party Advisory | |
secalert@redhat.com | https://bugzilla.redhat.com/show_bug.cgi?id=1132956 | Issue Tracking, Third Party Advisory | |
secalert@redhat.com | https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html | Patch, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16 | ||
af854a3a-2127-422b-91ae-364da2661108 | http://seclists.org/oss-sec/2014/q3/438 | Mailing List, Patch, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://seclists.org/oss-sec/2014/q3/440 | Mailing List, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | http://www.ubuntu.com/usn/USN-2409-1 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://bugzilla.redhat.com/show_bug.cgi?id=1132956 | Issue Tracking, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html | Patch, Third Party Advisory |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
qemu | qemu | * | |
canonical | ubuntu_linux | 10.04 | |
canonical | ubuntu_linux | 12.04 | |
canonical | ubuntu_linux | 14.04 | |
canonical | ubuntu_linux | 14.10 |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:*", "matchCriteriaId": "3002CD11-CEF2-4CAF-A883-3B5BF4E8503A", "versionEndIncluding": "2.1.3", "vulnerable": true } ], "negate": false, "operator": "OR" } ] }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*", "matchCriteriaId": "01EDA41C-6B2E-49AF-B503-EB3882265C11", "vulnerable": true }, { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*", "matchCriteriaId": "8D305F7A-D159-4716-AB26-5E38BB5CD991", "vulnerable": true }, { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*", "matchCriteriaId": "815D70A8-47D3-459C-A32C-9FEACA0659D1", "vulnerable": true }, { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*", "matchCriteriaId": "49A63F39-30BE-443F-AF10-6245587D3359", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption." }, { "lang": "es", "value": "Error de superaci\u00f3n de l\u00edmite (off-by-one) en la funci\u00f3n pci_read en ACPI PCI interfaz hotplug (hw/acpi/pcihp.c) en QEMU permite a usuarios locales invitados obtener informaci\u00f3n sensible y tener otro impacto no especificado relacionado con un dispositivo PCI manipulado que provoca da\u00f1os en la memoria." } ], "id": "CVE-2014-5388", "lastModified": "2025-04-12T10:46:40.837", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "LOW", "accessVector": "LOCAL", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 4.6, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 3.9, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ] }, "published": "2014-11-15T21:59:05.397", "references": [ { "source": "secalert@redhat.com", "url": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16" }, { "source": "secalert@redhat.com", "tags": [ "Mailing List", "Patch", "Third Party Advisory" ], "url": "http://seclists.org/oss-sec/2014/q3/438" }, { "source": "secalert@redhat.com", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://seclists.org/oss-sec/2014/q3/440" }, { "source": "secalert@redhat.com", "tags": [ "Third Party Advisory" ], "url": "http://www.ubuntu.com/usn/USN-2409-1" }, { "source": "secalert@redhat.com", "tags": [ "Issue Tracking", "Third Party Advisory" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1132956" }, { "source": "secalert@redhat.com", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://git.qemu.org/?p=qemu.git%3Ba=commit%3Bh=fa365d7cd11185237471823a5a33d36765454e16" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List", "Patch", "Third Party Advisory" ], "url": "http://seclists.org/oss-sec/2014/q3/438" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Mailing List", "Third Party Advisory" ], "url": "http://seclists.org/oss-sec/2014/q3/440" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "http://www.ubuntu.com/usn/USN-2409-1" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Issue Tracking", "Third Party Advisory" ], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1132956" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://lists.gnu.org/archive/html/qemu-devel/2014-08/msg03338.html" } ], "sourceIdentifier": "secalert@redhat.com", "vulnStatus": "Deferred", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-193" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…