suse-su-2016:2936-1
Vulnerability from csaf_suse
Published
2016-11-29 09:18
Modified
2016-11-29 09:18
Summary
Security update for qemu
Notes
Title of the patch
Security update for qemu
Description of the patch
This update for qemu fixes the following issues:
- Patch queue updated from https://gitlab.suse.de/virtualization/qemu.git SLE12
- Change package post script udevadm trigger calls to be device
specific (bsc#1002116)
- Address various security/stability issues
* Fix OOB access in xlnx.xpx-ethernetlite emulation (CVE-2016-7161 bsc#1001151)
* Fix OOB access in VMware SVGA emulation (CVE-2016-7170 bsc#998516)
* Fix DOS in Vmware pv scsi interface (CVE-2016-7421 bsc#999661)
* Fix DOS in ColdFire Fast Ethernet Controller emulation
(CVE-2016-7908 bsc#1002550)
* Fix DOS in USB xHCI emulation (CVE-2016-8576 bsc#1003878)
* Fix DOS in virtio-9pfs (CVE-2016-8578 bsc#1003894)
* Fix DOS in virtio-9pfs (CVE-2016-9105 bsc#1007494)
* Fix DOS in virtio-9pfs (CVE-2016-8577 bsc#1003893)
* Plug data leak in virtio-9pfs interface (CVE-2016-9103 bsc#1007454)
* Fix DOS in virtio-9pfs interface (CVE-2016-9102 bsc#1007450)
* Fix DOS in virtio-9pfs (CVE-2016-9106 bsc#1007495)
* Fix DOS in 16550A UART emulation (CVE-2016-8669 bsc#1004707)
* Fix DOS in PC-Net II emulation (CVE-2016-7909 bsc#1002557)
* Fix DOS in PRO100 emulation (CVE-2016-9101 bsc#1007391)
* Fix DOS in RTL8139 emulation (CVE-2016-8910 bsc#1006538)
* Fix DOS in Intel HDA controller emulation (CVE-2016-8909 bsc#1006536)
* Fix DOS in virtio-9pfs (CVE-2016-9104 bsc#1007493)
* Fix DOS in JAZZ RC4030 emulation (CVE-2016-8667 bsc#1004702)
Patchnames
SUSE-SLE-SAP-12-2016-1719,SUSE-SLE-SERVER-12-2016-1719
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "important" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for qemu", "title": "Title of the patch" }, { "category": "description", "text": "\nThis update for qemu fixes the following issues:\n\n- Patch queue updated from https://gitlab.suse.de/virtualization/qemu.git SLE12\n- Change package post script udevadm trigger calls to be device\n specific (bsc#1002116)\n- Address various security/stability issues\n * Fix OOB access in xlnx.xpx-ethernetlite emulation (CVE-2016-7161 bsc#1001151)\n * Fix OOB access in VMware SVGA emulation (CVE-2016-7170 bsc#998516)\n * Fix DOS in Vmware pv scsi interface (CVE-2016-7421 bsc#999661)\n * Fix DOS in ColdFire Fast Ethernet Controller emulation\n (CVE-2016-7908 bsc#1002550)\n * Fix DOS in USB xHCI emulation (CVE-2016-8576 bsc#1003878)\n * Fix DOS in virtio-9pfs (CVE-2016-8578 bsc#1003894)\n * Fix DOS in virtio-9pfs (CVE-2016-9105 bsc#1007494)\n * Fix DOS in virtio-9pfs (CVE-2016-8577 bsc#1003893)\n * Plug data leak in virtio-9pfs interface (CVE-2016-9103 bsc#1007454)\n * Fix DOS in virtio-9pfs interface (CVE-2016-9102 bsc#1007450)\n * Fix DOS in virtio-9pfs (CVE-2016-9106 bsc#1007495)\n * Fix DOS in 16550A UART emulation (CVE-2016-8669 bsc#1004707)\n * Fix DOS in PC-Net II emulation (CVE-2016-7909 bsc#1002557)\n * Fix DOS in PRO100 emulation (CVE-2016-9101 bsc#1007391)\n * Fix DOS in RTL8139 emulation (CVE-2016-8910 bsc#1006538)\n * Fix DOS in Intel HDA controller emulation (CVE-2016-8909 bsc#1006536)\n * Fix DOS in virtio-9pfs (CVE-2016-9104 bsc#1007493)\n * Fix DOS in JAZZ RC4030 emulation (CVE-2016-8667 bsc#1004702)\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-SLE-SAP-12-2016-1719,SUSE-SLE-SERVER-12-2016-1719", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2016_2936-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2016:2936-1", "url": "https://www.suse.com/support/update/announcement/2016/suse-su-20162936-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2016:2936-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2016-November/002426.html" }, { "category": "self", "summary": "SUSE Bug 1001151", "url": "https://bugzilla.suse.com/1001151" }, { "category": "self", "summary": "SUSE Bug 1002116", "url": "https://bugzilla.suse.com/1002116" }, { "category": "self", "summary": "SUSE Bug 1002550", "url": "https://bugzilla.suse.com/1002550" }, { "category": "self", "summary": "SUSE Bug 1002557", "url": "https://bugzilla.suse.com/1002557" }, { "category": "self", "summary": "SUSE Bug 1003878", "url": "https://bugzilla.suse.com/1003878" }, { "category": "self", "summary": "SUSE Bug 1003893", "url": "https://bugzilla.suse.com/1003893" }, { "category": "self", "summary": "SUSE Bug 1003894", "url": "https://bugzilla.suse.com/1003894" }, { "category": "self", "summary": "SUSE Bug 1004702", "url": "https://bugzilla.suse.com/1004702" }, { "category": "self", "summary": "SUSE Bug 1004707", "url": "https://bugzilla.suse.com/1004707" }, { "category": "self", "summary": "SUSE Bug 1006536", "url": "https://bugzilla.suse.com/1006536" }, { "category": "self", "summary": "SUSE Bug 1006538", "url": "https://bugzilla.suse.com/1006538" }, { "category": "self", "summary": "SUSE Bug 1007391", "url": "https://bugzilla.suse.com/1007391" }, { "category": "self", "summary": "SUSE Bug 1007450", "url": "https://bugzilla.suse.com/1007450" }, { "category": "self", "summary": "SUSE Bug 1007454", "url": "https://bugzilla.suse.com/1007454" }, { "category": "self", "summary": "SUSE Bug 1007493", "url": "https://bugzilla.suse.com/1007493" }, { "category": "self", "summary": "SUSE Bug 1007494", "url": "https://bugzilla.suse.com/1007494" }, { "category": "self", "summary": "SUSE Bug 1007495", "url": "https://bugzilla.suse.com/1007495" }, { "category": "self", "summary": "SUSE Bug 998516", "url": "https://bugzilla.suse.com/998516" }, { "category": "self", "summary": "SUSE Bug 999661", "url": "https://bugzilla.suse.com/999661" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7161 page", "url": "https://www.suse.com/security/cve/CVE-2016-7161/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7170 page", "url": "https://www.suse.com/security/cve/CVE-2016-7170/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7421 page", "url": "https://www.suse.com/security/cve/CVE-2016-7421/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7908 page", "url": "https://www.suse.com/security/cve/CVE-2016-7908/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-7909 page", "url": "https://www.suse.com/security/cve/CVE-2016-7909/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8576 page", "url": "https://www.suse.com/security/cve/CVE-2016-8576/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8577 page", "url": "https://www.suse.com/security/cve/CVE-2016-8577/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8578 page", "url": "https://www.suse.com/security/cve/CVE-2016-8578/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8667 page", "url": "https://www.suse.com/security/cve/CVE-2016-8667/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8669 page", "url": "https://www.suse.com/security/cve/CVE-2016-8669/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8909 page", "url": "https://www.suse.com/security/cve/CVE-2016-8909/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-8910 page", "url": "https://www.suse.com/security/cve/CVE-2016-8910/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-9101 page", "url": "https://www.suse.com/security/cve/CVE-2016-9101/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-9102 page", "url": "https://www.suse.com/security/cve/CVE-2016-9102/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-9103 page", "url": "https://www.suse.com/security/cve/CVE-2016-9103/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-9104 page", "url": "https://www.suse.com/security/cve/CVE-2016-9104/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-9105 page", "url": "https://www.suse.com/security/cve/CVE-2016-9105/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-9106 page", "url": "https://www.suse.com/security/cve/CVE-2016-9106/" } ], "title": "Security update for qemu", "tracking": { "current_release_date": "2016-11-29T09:18:32Z", "generator": { "date": "2016-11-29T09:18:32Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2016:2936-1", "initial_release_date": "2016-11-29T09:18:32Z", "revision_history": [ { "date": "2016-11-29T09:18:32Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "qemu-ipxe-1.0.0-48.25.1.noarch", "product": { "name": "qemu-ipxe-1.0.0-48.25.1.noarch", "product_id": "qemu-ipxe-1.0.0-48.25.1.noarch" } }, { "category": "product_version", "name": "qemu-seabios-1.7.4-48.25.1.noarch", "product": { "name": "qemu-seabios-1.7.4-48.25.1.noarch", "product_id": "qemu-seabios-1.7.4-48.25.1.noarch" } }, { "category": "product_version", "name": "qemu-sgabios-8-48.25.1.noarch", "product": { "name": "qemu-sgabios-8-48.25.1.noarch", "product_id": "qemu-sgabios-8-48.25.1.noarch" } }, { "category": "product_version", "name": "qemu-vgabios-1.7.4-48.25.1.noarch", "product": { "name": "qemu-vgabios-1.7.4-48.25.1.noarch", "product_id": "qemu-vgabios-1.7.4-48.25.1.noarch" } } ], "category": "architecture", "name": "noarch" }, { "branches": [ { "category": "product_version", "name": "qemu-2.0.2-48.25.1.ppc64le", "product": { "name": "qemu-2.0.2-48.25.1.ppc64le", "product_id": "qemu-2.0.2-48.25.1.ppc64le" } }, { "category": "product_version", "name": "qemu-block-curl-2.0.2-48.25.1.ppc64le", "product": { "name": "qemu-block-curl-2.0.2-48.25.1.ppc64le", "product_id": "qemu-block-curl-2.0.2-48.25.1.ppc64le" } }, { "category": "product_version", "name": "qemu-guest-agent-2.0.2-48.25.1.ppc64le", "product": { "name": "qemu-guest-agent-2.0.2-48.25.1.ppc64le", "product_id": "qemu-guest-agent-2.0.2-48.25.1.ppc64le" } }, { "category": "product_version", "name": "qemu-lang-2.0.2-48.25.1.ppc64le", "product": { "name": "qemu-lang-2.0.2-48.25.1.ppc64le", "product_id": "qemu-lang-2.0.2-48.25.1.ppc64le" } }, { "category": "product_version", "name": "qemu-ppc-2.0.2-48.25.1.ppc64le", "product": { "name": "qemu-ppc-2.0.2-48.25.1.ppc64le", "product_id": "qemu-ppc-2.0.2-48.25.1.ppc64le" } }, { "category": "product_version", "name": "qemu-tools-2.0.2-48.25.1.ppc64le", "product": { "name": "qemu-tools-2.0.2-48.25.1.ppc64le", "product_id": "qemu-tools-2.0.2-48.25.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "qemu-2.0.2-48.25.1.s390x", "product": { "name": "qemu-2.0.2-48.25.1.s390x", "product_id": "qemu-2.0.2-48.25.1.s390x" } }, { "category": "product_version", "name": "qemu-block-curl-2.0.2-48.25.1.s390x", "product": { "name": "qemu-block-curl-2.0.2-48.25.1.s390x", "product_id": "qemu-block-curl-2.0.2-48.25.1.s390x" } }, { "category": "product_version", "name": "qemu-guest-agent-2.0.2-48.25.1.s390x", "product": { "name": "qemu-guest-agent-2.0.2-48.25.1.s390x", "product_id": "qemu-guest-agent-2.0.2-48.25.1.s390x" } }, { "category": "product_version", "name": "qemu-kvm-2.0.2-48.25.1.s390x", "product": { "name": "qemu-kvm-2.0.2-48.25.1.s390x", "product_id": "qemu-kvm-2.0.2-48.25.1.s390x" } }, { "category": "product_version", "name": "qemu-lang-2.0.2-48.25.1.s390x", "product": { "name": "qemu-lang-2.0.2-48.25.1.s390x", "product_id": "qemu-lang-2.0.2-48.25.1.s390x" } }, { "category": "product_version", "name": "qemu-s390-2.0.2-48.25.1.s390x", "product": { "name": "qemu-s390-2.0.2-48.25.1.s390x", "product_id": "qemu-s390-2.0.2-48.25.1.s390x" } }, { "category": "product_version", "name": "qemu-tools-2.0.2-48.25.1.s390x", "product": { "name": "qemu-tools-2.0.2-48.25.1.s390x", "product_id": "qemu-tools-2.0.2-48.25.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "qemu-2.0.2-48.25.1.x86_64", "product": { "name": "qemu-2.0.2-48.25.1.x86_64", "product_id": "qemu-2.0.2-48.25.1.x86_64" } }, { "category": "product_version", "name": "qemu-block-curl-2.0.2-48.25.1.x86_64", "product": { "name": "qemu-block-curl-2.0.2-48.25.1.x86_64", "product_id": "qemu-block-curl-2.0.2-48.25.1.x86_64" } }, { "category": "product_version", "name": "qemu-block-rbd-2.0.2-48.25.1.x86_64", "product": { "name": "qemu-block-rbd-2.0.2-48.25.1.x86_64", "product_id": "qemu-block-rbd-2.0.2-48.25.1.x86_64" } }, { "category": "product_version", "name": "qemu-guest-agent-2.0.2-48.25.1.x86_64", "product": { "name": "qemu-guest-agent-2.0.2-48.25.1.x86_64", "product_id": "qemu-guest-agent-2.0.2-48.25.1.x86_64" } }, { "category": "product_version", "name": "qemu-kvm-2.0.2-48.25.1.x86_64", "product": { "name": "qemu-kvm-2.0.2-48.25.1.x86_64", "product_id": "qemu-kvm-2.0.2-48.25.1.x86_64" } }, { "category": "product_version", "name": "qemu-lang-2.0.2-48.25.1.x86_64", "product": { "name": "qemu-lang-2.0.2-48.25.1.x86_64", "product_id": "qemu-lang-2.0.2-48.25.1.x86_64" } }, { "category": "product_version", "name": "qemu-tools-2.0.2-48.25.1.x86_64", "product": { "name": "qemu-tools-2.0.2-48.25.1.x86_64", "product_id": "qemu-tools-2.0.2-48.25.1.x86_64" } }, { "category": "product_version", "name": "qemu-x86-2.0.2-48.25.1.x86_64", "product": { "name": "qemu-x86-2.0.2-48.25.1.x86_64", "product_id": "qemu-x86-2.0.2-48.25.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux Enterprise Server for SAP Applications 12", "product": { "name": "SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12", "product_identification_helper": { "cpe": "cpe:/o:suse:sles_sap:12" } } }, { "category": "product_name", "name": "SUSE Linux Enterprise Server 12-LTSS", "product": { "name": "SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS", "product_identification_helper": { "cpe": "cpe:/o:suse:sles-ltss:12" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "qemu-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-curl-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-block-curl-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-rbd-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-block-rbd-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-guest-agent-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-guest-agent-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-ipxe-1.0.0-48.25.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch" }, "product_reference": "qemu-ipxe-1.0.0-48.25.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-kvm-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-kvm-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-lang-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-lang-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-seabios-1.7.4-48.25.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch" }, "product_reference": "qemu-seabios-1.7.4-48.25.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-sgabios-8-48.25.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch" }, "product_reference": "qemu-sgabios-8-48.25.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-tools-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-tools-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-vgabios-1.7.4-48.25.1.noarch as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch" }, "product_reference": "qemu-vgabios-1.7.4-48.25.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-x86-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server for SAP Applications 12", "product_id": "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-x86-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server for SAP Applications 12" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-2.0.2-48.25.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le" }, "product_reference": "qemu-2.0.2-48.25.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-2.0.2-48.25.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x" }, "product_reference": "qemu-2.0.2-48.25.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-curl-2.0.2-48.25.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le" }, "product_reference": "qemu-block-curl-2.0.2-48.25.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-curl-2.0.2-48.25.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x" }, "product_reference": "qemu-block-curl-2.0.2-48.25.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-curl-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-block-curl-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-block-rbd-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-block-rbd-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-guest-agent-2.0.2-48.25.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le" }, "product_reference": "qemu-guest-agent-2.0.2-48.25.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-guest-agent-2.0.2-48.25.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x" }, "product_reference": "qemu-guest-agent-2.0.2-48.25.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-guest-agent-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-guest-agent-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-ipxe-1.0.0-48.25.1.noarch as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch" }, "product_reference": "qemu-ipxe-1.0.0-48.25.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-kvm-2.0.2-48.25.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x" }, "product_reference": "qemu-kvm-2.0.2-48.25.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-kvm-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-kvm-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-lang-2.0.2-48.25.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le" }, "product_reference": "qemu-lang-2.0.2-48.25.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-lang-2.0.2-48.25.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x" }, "product_reference": "qemu-lang-2.0.2-48.25.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-lang-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-lang-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-ppc-2.0.2-48.25.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le" }, "product_reference": "qemu-ppc-2.0.2-48.25.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-s390-2.0.2-48.25.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x" }, "product_reference": "qemu-s390-2.0.2-48.25.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-seabios-1.7.4-48.25.1.noarch as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch" }, "product_reference": "qemu-seabios-1.7.4-48.25.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-sgabios-8-48.25.1.noarch as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch" }, "product_reference": "qemu-sgabios-8-48.25.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-tools-2.0.2-48.25.1.ppc64le as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le" }, "product_reference": "qemu-tools-2.0.2-48.25.1.ppc64le", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-tools-2.0.2-48.25.1.s390x as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x" }, "product_reference": "qemu-tools-2.0.2-48.25.1.s390x", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-tools-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-tools-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-vgabios-1.7.4-48.25.1.noarch as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch" }, "product_reference": "qemu-vgabios-1.7.4-48.25.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" }, { "category": "default_component_of", "full_product_name": { "name": "qemu-x86-2.0.2-48.25.1.x86_64 as component of SUSE Linux Enterprise Server 12-LTSS", "product_id": "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64" }, "product_reference": "qemu-x86-2.0.2-48.25.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Server 12-LTSS" } ] }, "vulnerabilities": [ { "cve": "CVE-2016-7161", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7161" } ], "notes": [ { "category": "general", "text": "Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7161", "url": "https://www.suse.com/security/cve/CVE-2016-7161" }, { "category": "external", "summary": "SUSE Bug 1001151 for CVE-2016-7161", "url": "https://bugzilla.suse.com/1001151" }, { "category": "external", "summary": "SUSE Bug 1001152 for CVE-2016-7161", "url": "https://bugzilla.suse.com/1001152" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 9.8, "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-7161" }, { "cve": "CVE-2016-7170", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7170" } ], "notes": [ { "category": "general", "text": "The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[] array sizes when processing a DEFINE_CURSOR svga command.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7170", "url": "https://www.suse.com/security/cve/CVE-2016-7170" }, { "category": "external", "summary": "SUSE Bug 998516 for CVE-2016-7170", "url": "https://bugzilla.suse.com/998516" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-7170" }, { "cve": "CVE-2016-7421", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7421" } ], "notes": [ { "category": "general", "text": "The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7421", "url": "https://www.suse.com/security/cve/CVE-2016-7421" }, { "category": "external", "summary": "SUSE Bug 999661 for CVE-2016-7421", "url": "https://bugzilla.suse.com/999661" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "low" } ], "title": "CVE-2016-7421" }, { "cve": "CVE-2016-7908", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7908" } ], "notes": [ { "category": "general", "text": "The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7908", "url": "https://www.suse.com/security/cve/CVE-2016-7908" }, { "category": "external", "summary": "SUSE Bug 1002550 for CVE-2016-7908", "url": "https://bugzilla.suse.com/1002550" }, { "category": "external", "summary": "SUSE Bug 1003030 for CVE-2016-7908", "url": "https://bugzilla.suse.com/1003030" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-7908" }, { "cve": "CVE-2016-7909", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-7909" } ], "notes": [ { "category": "general", "text": "The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-7909", "url": "https://www.suse.com/security/cve/CVE-2016-7909" }, { "category": "external", "summary": "SUSE Bug 1002557 for CVE-2016-7909", "url": "https://bugzilla.suse.com/1002557" }, { "category": "external", "summary": "SUSE Bug 1003032 for CVE-2016-7909", "url": "https://bugzilla.suse.com/1003032" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-7909" }, { "cve": "CVE-2016-8576", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8576" } ], "notes": [ { "category": "general", "text": "The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8576", "url": "https://www.suse.com/security/cve/CVE-2016-8576" }, { "category": "external", "summary": "SUSE Bug 1003878 for CVE-2016-8576", "url": "https://bugzilla.suse.com/1003878" }, { "category": "external", "summary": "SUSE Bug 1004016 for CVE-2016-8576", "url": "https://bugzilla.suse.com/1004016" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-8576" }, { "cve": "CVE-2016-8577", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8577" } ], "notes": [ { "category": "general", "text": "Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8577", "url": "https://www.suse.com/security/cve/CVE-2016-8577" }, { "category": "external", "summary": "SUSE Bug 1003893 for CVE-2016-8577", "url": "https://bugzilla.suse.com/1003893" }, { "category": "external", "summary": "SUSE Bug 1004021 for CVE-2016-8577", "url": "https://bugzilla.suse.com/1004021" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-8577" }, { "cve": "CVE-2016-8578", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8578" } ], "notes": [ { "category": "general", "text": "The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an empty string parameter to a 9P operation.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8578", "url": "https://www.suse.com/security/cve/CVE-2016-8578" }, { "category": "external", "summary": "SUSE Bug 1003894 for CVE-2016-8578", "url": "https://bugzilla.suse.com/1003894" }, { "category": "external", "summary": "SUSE Bug 1004023 for CVE-2016-8578", "url": "https://bugzilla.suse.com/1004023" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-8578" }, { "cve": "CVE-2016-8667", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8667" } ], "notes": [ { "category": "general", "text": "The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload value.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8667", "url": "https://www.suse.com/security/cve/CVE-2016-8667" }, { "category": "external", "summary": "SUSE Bug 1004702 for CVE-2016-8667", "url": "https://bugzilla.suse.com/1004702" }, { "category": "external", "summary": "SUSE Bug 1005004 for CVE-2016-8667", "url": "https://bugzilla.suse.com/1005004" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-8667" }, { "cve": "CVE-2016-8669", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8669" } ], "notes": [ { "category": "general", "text": "The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8669", "url": "https://www.suse.com/security/cve/CVE-2016-8669" }, { "category": "external", "summary": "SUSE Bug 1004707 for CVE-2016-8669", "url": "https://bugzilla.suse.com/1004707" }, { "category": "external", "summary": "SUSE Bug 1005005 for CVE-2016-8669", "url": "https://bugzilla.suse.com/1005005" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-8669" }, { "cve": "CVE-2016-8909", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8909" } ], "notes": [ { "category": "general", "text": "The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8909", "url": "https://www.suse.com/security/cve/CVE-2016-8909" }, { "category": "external", "summary": "SUSE Bug 1006536 for CVE-2016-8909", "url": "https://bugzilla.suse.com/1006536" }, { "category": "external", "summary": "SUSE Bug 1007160 for CVE-2016-8909", "url": "https://bugzilla.suse.com/1007160" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "low" } ], "title": "CVE-2016-8909" }, { "cve": "CVE-2016-8910", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-8910" } ], "notes": [ { "category": "general", "text": "The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-8910", "url": "https://www.suse.com/security/cve/CVE-2016-8910" }, { "category": "external", "summary": "SUSE Bug 1006538 for CVE-2016-8910", "url": "https://bugzilla.suse.com/1006538" }, { "category": "external", "summary": "SUSE Bug 1007157 for CVE-2016-8910", "url": "https://bugzilla.suse.com/1007157" }, { "category": "external", "summary": "SUSE Bug 1024178 for CVE-2016-8910", "url": "https://bugzilla.suse.com/1024178" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "low" } ], "title": "CVE-2016-8910" }, { "cve": "CVE-2016-9101", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-9101" } ], "notes": [ { "category": "general", "text": "Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-9101", "url": "https://www.suse.com/security/cve/CVE-2016-9101" }, { "category": "external", "summary": "SUSE Bug 1007391 for CVE-2016-9101", "url": "https://bugzilla.suse.com/1007391" }, { "category": "external", "summary": "SUSE Bug 1013668 for CVE-2016-9101", "url": "https://bugzilla.suse.com/1013668" }, { "category": "external", "summary": "SUSE Bug 1024181 for CVE-2016-9101", "url": "https://bugzilla.suse.com/1024181" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "low" } ], "title": "CVE-2016-9101" }, { "cve": "CVE-2016-9102", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-9102" } ], "notes": [ { "category": "general", "text": "Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with the same fid number.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-9102", "url": "https://www.suse.com/security/cve/CVE-2016-9102" }, { "category": "external", "summary": "SUSE Bug 1007450 for CVE-2016-9102", "url": "https://bugzilla.suse.com/1007450" }, { "category": "external", "summary": "SUSE Bug 1014256 for CVE-2016-9102", "url": "https://bugzilla.suse.com/1014256" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "moderate" } ], "title": "CVE-2016-9102" }, { "cve": "CVE-2016-9103", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-9103" } ], "notes": [ { "category": "general", "text": "The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-9103", "url": "https://www.suse.com/security/cve/CVE-2016-9103" }, { "category": "external", "summary": "SUSE Bug 1007454 for CVE-2016-9103", "url": "https://bugzilla.suse.com/1007454" }, { "category": "external", "summary": "SUSE Bug 1014259 for CVE-2016-9103", "url": "https://bugzilla.suse.com/1014259" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "low" } ], "title": "CVE-2016-9103" }, { "cve": "CVE-2016-9104", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-9104" } ], "notes": [ { "category": "general", "text": "Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which triggers an out-of-bounds access.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-9104", "url": "https://www.suse.com/security/cve/CVE-2016-9104" }, { "category": "external", "summary": "SUSE Bug 1007493 for CVE-2016-9104", "url": "https://bugzilla.suse.com/1007493" }, { "category": "external", "summary": "SUSE Bug 1014297 for CVE-2016-9104", "url": "https://bugzilla.suse.com/1014297" }, { "category": "external", "summary": "SUSE Bug 1034990 for CVE-2016-9104", "url": "https://bugzilla.suse.com/1034990" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "low" } ], "title": "CVE-2016-9104" }, { "cve": "CVE-2016-9105", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-9105" } ], "notes": [ { "category": "general", "text": "Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a reference to the source fid object.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-9105", "url": "https://www.suse.com/security/cve/CVE-2016-9105" }, { "category": "external", "summary": "SUSE Bug 1007494 for CVE-2016-9105", "url": "https://bugzilla.suse.com/1007494" }, { "category": "external", "summary": "SUSE Bug 1014279 for CVE-2016-9105", "url": "https://bugzilla.suse.com/1014279" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "low" } ], "title": "CVE-2016-9105" }, { "cve": "CVE-2016-9106", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-9106" } ], "notes": [ { "category": "general", "text": "Memory leak in the v9fs_write function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) by leveraging failure to free an IO vector.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-9106", "url": "https://www.suse.com/security/cve/CVE-2016-9106" }, { "category": "external", "summary": "SUSE Bug 1007495 for CVE-2016-9106", "url": "https://bugzilla.suse.com/1007495" }, { "category": "external", "summary": "SUSE Bug 1014299 for CVE-2016-9106", "url": "https://bugzilla.suse.com/1014299" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-ppc-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-s390-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.ppc64le", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.s390x", "SUSE Linux Enterprise Server 12-LTSS:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server 12-LTSS:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server 12-LTSS:qemu-x86-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-curl-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-block-rbd-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-guest-agent-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-ipxe-1.0.0-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-kvm-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-lang-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-seabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-sgabios-8-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-tools-2.0.2-48.25.1.x86_64", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-vgabios-1.7.4-48.25.1.noarch", "SUSE Linux Enterprise Server for SAP Applications 12:qemu-x86-2.0.2-48.25.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-11-29T09:18:32Z", "details": "low" } ], "title": "CVE-2016-9106" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…