RHSA-2015:1003-1: Important: kvm security update

Red Hat Enterprise Linux: Updated kvm packages that fix one security issue are now available for Red
Hat Enterprise Linux 5.

Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-3456

RHSA-2015:1002-1: Important: xen security update

Red Hat Enterprise Linux: Updated xen packages that fix one security issue are now available for Red
Hat Enterprise Linux 5.

Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-3456

RHSA-2015:1001-1: Important: qemu-kvm-rhev security update

Red Hat Enterprise Linux: Updated qemu-kvm-rhev packages that fix one security issue are now
available for Red Hat Enterprise Virtualization 3.5.

Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-3456

RHSA-2015:1000-1: Important: qemu-kvm-rhev security update

Red Hat Enterprise Linux: Updated qemu-kvm-rhev packages that fix one security issue are now
available for Red Hat Enterprise Virtualization Hypervisor 7.

Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-3456

RHSA-2015:0999-1: Important: qemu-kvm security update

Red Hat Enterprise Linux: Updated qemu-kvm packages that fix one security issue are now available for
Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-3456

RHSA-2015:0998-1: Important: qemu-kvm security update

Red Hat Enterprise Linux: Updated qemu-kvm packages that fix one security issue are now available for
Red Hat Enterprise Linux 6.

Red Hat Product Security has rated this update as having Important security
impact. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available from the CVE link in the
References section.
CVE-2015-3456

USN-2608-1: QEMU vulnerabilities

Ubuntu Security Notice USN-2608-1

13th May, 2015

qemu, qemu-kvm vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu (vivid)
  • Ubuntu 14.10
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Several security issues were fixed in QEMU.

Software description

  • qemu
    – Machine emulator and virtualizer

  • qemu-kvm
    – Machine emulator and virtualizer

Details

Jason Geffner discovered that QEMU incorrectly handled the virtual floppy
driver. This issue is known as VENOM. A malicious guest could use this
issue to cause a denial of service, or possibly execute arbitrary code on
the host as the user running the QEMU process. In the default installation,
when QEMU is used with libvirt, attackers would be isolated by the libvirt
AppArmor profile. (CVE-2015-3456)

Daniel P. Berrange discovered that QEMU incorrectly handled VNC websockets.
A remote attacker could use this issue to cause QEMU to consume memory,
resulting in a denial of service. This issue only affected Ubuntu 14.04
LTS, Ubuntu 14.10 and Ubuntu 15.04. (CVE-2015-1779)

Jan Beulich discovered that QEMU, when used with Xen, didn’t properly
restrict access to PCI command registers. A malicious guest could use this
issue to cause a denial of service. This issue only affected Ubuntu 14.04
LTS and Ubuntu 14.10. (CVE-2015-2756)

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu (vivid):
qemu-system-misc

1:2.2+dfsg-5expubuntu9.1
qemu-system

1:2.2+dfsg-5expubuntu9.1
qemu-system-aarch64

1:2.2+dfsg-5expubuntu9.1
qemu-system-x86

1:2.2+dfsg-5expubuntu9.1
qemu-system-sparc

1:2.2+dfsg-5expubuntu9.1
qemu-system-arm

1:2.2+dfsg-5expubuntu9.1
qemu-system-ppc

1:2.2+dfsg-5expubuntu9.1
qemu-system-mips

1:2.2+dfsg-5expubuntu9.1
Ubuntu 14.10:
qemu-system-misc

2.1+dfsg-4ubuntu6.6
qemu-system

2.1+dfsg-4ubuntu6.6
qemu-system-aarch64

2.1+dfsg-4ubuntu6.6
qemu-system-x86

2.1+dfsg-4ubuntu6.6
qemu-system-sparc

2.1+dfsg-4ubuntu6.6
qemu-system-arm

2.1+dfsg-4ubuntu6.6
qemu-system-ppc

2.1+dfsg-4ubuntu6.6
qemu-system-mips

2.1+dfsg-4ubuntu6.6
Ubuntu 14.04 LTS:
qemu-system-misc

2.0.0+dfsg-2ubuntu1.11
qemu-system

2.0.0+dfsg-2ubuntu1.11
qemu-system-aarch64

2.0.0+dfsg-2ubuntu1.11
qemu-system-x86

2.0.0+dfsg-2ubuntu1.11
qemu-system-sparc

2.0.0+dfsg-2ubuntu1.11
qemu-system-arm

2.0.0+dfsg-2ubuntu1.11
qemu-system-ppc

2.0.0+dfsg-2ubuntu1.11
qemu-system-mips

2.0.0+dfsg-2ubuntu1.11
Ubuntu 12.04 LTS:
qemu-kvm

1.0+noroms-0ubuntu14.22

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart all QEMU virtual
machines to make all the necessary changes.

References

CVE-2015-1779,

CVE-2015-2756,

CVE-2015-3456

USN-2602-1: Firefox vulnerabilities

Ubuntu Security Notice USN-2602-1

13th May, 2015

firefox vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu (vivid)
  • Ubuntu 14.10
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Firefox could be made to crash or run programs as your login if it
opened a malicious website.

Software description

  • firefox
    – Mozilla Open Source web browser

Details

Jesse Ruderman, Mats Palmgren, Byron Campen, Steve Fink, Gary Kwong,
Andrew McCreight, Christian Holler, Jon Coppeard, and Milan Sreckovic
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-2708, CVE-2015-2709)

Atte Kettunen discovered a buffer overflow during the rendering of SVG
content with certain CSS properties in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-2710)

Alex Verstak discovered that <meta name=”referrer”> is ignored in some
circumstances. (CVE-2015-2711)

Dougall Johnson discovered an out of bounds read and write in asm.js. If
a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to obtain sensitive information,
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-2712)

Scott Bell discovered a use-afer-free during the processing of text when
vertical text is enabled. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2713)

Tyson Smith and Jesse Schwartzentruber discovered a use-after-free during
shutdown. An attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2015-2715)

Ucha Gobejishvili discovered a buffer overflow when parsing compressed XML
content. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit this to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2015-2716)

A buffer overflow and out-of-bounds read were discovered when parsing
metadata in MP4 files in some circumstances. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via application crash, or execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2015-2717)

Mark Hammond discovered that when a trusted page is hosted within an
iframe in an untrusted page, the untrusted page can intercept webchannel
responses meant for the trusted page in some circumstances. If a user
were tricked in to opening a specially crafted website, an attacker could
exploit this to bypass origin restrictions. (CVE-2015-2718)

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu (vivid):
firefox

38.0+build3-0ubuntu0.15.04.1
Ubuntu 14.10:
firefox

38.0+build3-0ubuntu0.14.10.1
Ubuntu 14.04 LTS:
firefox

38.0+build3-0ubuntu0.14.04.1
Ubuntu 12.04 LTS:
firefox

38.0+build3-0ubuntu0.12.04.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

CVE-2015-2708,

CVE-2015-2709,

CVE-2015-2710,

CVE-2015-2711,

CVE-2015-2712,

CVE-2015-2713,

CVE-2015-2715,

CVE-2015-2716,

CVE-2015-2717,

CVE-2015-2718