CNNVD-ID编号 | CNNVD-201909-256 | CVE编号 | CVE-2019-15890 |
发布时间 | 2019-09-06 | 更新时间 | 2020-11-05 |
漏洞类型 | 资源管理错误 | 漏洞来源 | Ubuntu,Debian,Red Hat |
危险等级 | 高危 | 威胁类型 | 远程 |
厂商 | N/A |
QEMU(Quick Emulator)是法国法布里斯-贝拉(Fabrice Bellard)软件开发者的一套模拟处理器软件。该软件具有速度快、跨平台等特点。libslirp是一款用于在虚拟机管理程序中管理虚拟网络服务的通用TCP-IP模拟器。
QEMU 4.1.0版本中使用的libslirp 4.0.0版本的ip_input.c文件的‘ip_reass’函数存在资源管理错误漏洞。该漏洞源于网络系统或产品对系统资源(如内存、磁盘空间、文件等)的管理不当。
目前厂商已发布升级了QEMU libslirp 资源管理错误漏洞的补丁,QEMU libslirp 资源管理错误漏洞的补丁获取链接:
https://gitlab.freedesktop.org/slirp/libslirp/commit/c59279437eda91841b9d26079c70b8a540d41204
来源:gitlab.freedesktop.org
链接:https://gitlab.freedesktop.org/slirp/libslirp/commit/c5927943
来源:www.openwall.com
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2019/09/msg00021.html
来源:lists.debian.org
链接:https://lists.debian.org/debian-lts-announce/2019/09/msg00021.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192956-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192955-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192954-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192783-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-201914199-1.htm
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192769-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20192753-1.html
来源:usn.ubuntu.com
来源:usn.ubuntu.com
来源:www.debian.org
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/QEMU-use-after-free-via-SLiRP-Packet-Reassembly-30265
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156803/Red-Hat-Security-Advisory-2020-0889-01.html
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159823/Red-Hat-Security-Advisory-2020-4676-01.html
来源:www.auscert.org.au
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/155337/Ubuntu-Security-Notice-USN-4191-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156187/Debian-Security-Advisory-4616-1.html
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:nvd.nist.gov
来源:www.auscert.org.au
暂无