USN-4372-1
Dashboard / Vulnerabilities / USN-4372-1
USN-4372-1
Summary: qemu vulnerabilities
Details: It was discovered that QEMU incorrectly handled bochs-display devices. A local attacker in a guest could use this to cause a denial of service or possibly execute arbitrary code in the host. This issue only affected Ubuntu 19.10. (CVE-2019-15034) It was discovered that QEMU incorrectly handled memory during certain VNC operations. A remote attacker could possibly use this issue to cause QEMU to consume resources, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10. (CVE-2019-20382) It was discovered that QEMU incorrectly generated QEMU Pointer Authentication signatures on ARM. A local attacker could possibly use this issue to bypass PAuth. This issue only affected Ubuntu 19.10. (CVE-2020-10702) Ziming Zhang discovered that QEMU incorrectly handled ATI VGA emulation. A local attacker in a guest could use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-11869) Aviv Sasson discovered that QEMU incorrectly handled Slirp networking. A remote attacker could use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10. (CVE-2020-1983)
References: https://ubuntu.com/security/notices/USN-4372-1, https://ubuntu.com/security/CVE-2019-15034, https://ubuntu.com/security/CVE-2019-20382, https://ubuntu.com/security/CVE-2020-1983, https://ubuntu.com/security/CVE-2020-10702, https://ubuntu.com/security/CVE-2020-11869
Affected packages
Package
Name: qemu
Purl: pkg:deb/ubuntu/qemu@1:2.5+dfsg-5ubuntu10.44?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
