USN-3575-1: QEMU vulnerabilities
USN-3575-1: QEMU vulnerabilities Ubuntu Security Notice USN-3575-1 20th February, 2018 qemu vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in QEMU. Software description qemu – Machine emulator and virtualizer Details It was discovered that QEMU incorrectly handled guest ram. A privilegedattacker inside the guest could use this issue to cause QEMU to crash,resulting in a denial of service. This issue only affected Ubuntu 14.04 LTSand Ubuntu 16.04 LTS. (CVE-2017-11334) David Buchanan discovered that QEMU incorrectly handled the VGA device. Aprivileged attacker inside the guest could use this issue to cause QEMU tocrash, resulting in a denial of service. This issue was only addressed inUbuntu 17.10. (CVE-2017-13672) Thomas Garnier discovered that QEMU incorrectly handled multiboot. Anattacker could use this issue to cause QEMU [ more… ]