SB2016081011 - Information disclosure in QEMU
Published: August 10, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) IP header length checking flaw (CVE-ID: N/A)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to obtain potentially sensitive information.
The vulnerability exists due improper check of IP header length values. A local user can obtain potentially sensitive information on the target system.
Systems with VMWARE VMXNET3 NIC device support are affected.
Successful exploitation of this vulnerability may result in disclosure of system information.
2) Vmxnet3 device emulator bug in processing transmit queue (CVE-ID: N/A)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows an adjacent user to obtain potentially sensitive information on the host system.
The vulnerability exists in QEMU. An adjacent attacker can obtain information on the host system by causing an information leak in the transmit queue processing.
Systems wtih VMWARE VMXNET3 NIC device support are affected.
Successful exploitation of this vulnerability may result in disclosure of system information.
Remediation
Install update from vendor's website.