Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in QEMU
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in QEMU
ID: USN-1177-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 10.10, Ubuntu 11.04
Datum: Mi, 27. Juli 2011, 19:12
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2527
Applikationen: QEMU

Originalnachricht


--===============3839735756054229621==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-et6TCgTMTarAa/1SsGjU"


--=-et6TCgTMTarAa/1SsGjU
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1177-1
July 27, 2011

qemu-kvm vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.04
- Ubuntu 10.10
- Ubuntu 10.04 LTS

Summary:

QEMU could be made to run with adminstrator group privileges under certain
circumstances.

Software Description:
- qemu-kvm: Machine emulator and virtualizer

Details:

Andrew Griffiths discovered that QEMU did not correctly drop privileges
when using the 'runas' argument. Under certain circumstances a local
attacker could exploit this to escalate privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
qemu-kvm 0.14.0+noroms-0ubuntu4.4

Ubuntu 10.10:
qemu-kvm 0.12.5+noroms-0ubuntu7.10
qemu-kvm-extras 0.12.5+noroms-0ubuntu7.10
qemu-kvm-extras-static 0.12.5+noroms-0ubuntu7.10

Ubuntu 10.04 LTS:
qemu-kvm 0.12.3+noroms-0ubuntu9.15
qemu-kvm-extras 0.12.3+noroms-0ubuntu9.15
qemu-kvm-extras-static 0.12.3+noroms-0ubuntu9.15

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1177-1
CVE-2011-2527

Package Information:
https://launchpad.net/ubuntu/+source/qemu-kvm/0.14.0+noroms-0ubuntu4.4
https://launchpad.net/ubuntu/+source/qemu-kvm/0.12.5+noroms-0ubuntu7.10
https://launchpad.net/ubuntu/+source/qemu-kvm/0.12.3+noroms-0ubuntu9.15



--Þt6TCgTMTarAa/1SsGjU
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJOMEGDAAoJEFHb3FjMVZVzUl8QAJ4XbIdX2peOyar6tVBzGi2t
5T1L9vM61bnd1dommri+HAcrJ7DixFSCHuVFkrOLko6SITxULqSQe03SjKeF8fO9
nHASYRjsYH7Z3/o5LJ7XQ1uv9EjwIuabH1UnbeEk/kCgeaCbsHm5EhKnVWNH593x
QJIISTTNAFJTQwojnrqaF/xly9yoev/+B0+PMcGc3eDlkpJ1qmgHiSchDBhB5Cwy
4YHi7Xu/NroI/IRgOI6BITKRsnBZ2HCGh/Jp9MWd3EGNAXN6C0reSMUQswkeOV9A
8CdhlYfKsLOD70JdGZ61n76qX7P8N6fXo3TznVdvzpTt1iTgeeQCt7VsdcuKCaEm
LihPu3JMiAui8HK7B02T+qkR16TslsPaoHYEsVdAgQOeOpGT49R1xqWHvk+lvE0/
7AcGn0Z51wNzM5YKo6FNbH2LF6pG3PNaZAVRutfPBXDpI9mD89hcTVu7PCNCxxqW
z+lK96tr3EqL59CAo/S64N/rfuiL9fRBCjwBOsVsFhUehHZpcUZeGKYXd7llzc8G
FEvtals9u0+b0GdUBRN8Bbn48QLEvhQd2bXgktGSRmTKex1EOThcl5jURxPmta8q
Un5ZQo0JFygmo49rlS5Ob97RxzhNZs3jptlEAvZZoJrv9nR0DH/JAurkJb/CLTOi
gqHr60O+X9ksg03f8pO+
=IDs1
-----END PGP SIGNATURE-----

--=-et6TCgTMTarAa/1SsGjU--



--===============3839735756054229621==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============3839735756054229621==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung