Ubuntu Security Notice (C) 2009-2013 Canonical, Inc. / NASL script (C) 2009-2013 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related patches.
Avi Kivity discovered that KVM did not correctly handle certain disk
formats. A local attacker could attach a malicious partition that
would allow the guest VM to read files on the VM host. (CVE-2008-1945,
Alfredo Ortega discovered that KVM's VNC protocol handler did not
correctly validate certain messages. A remote attacker could send
specially crafted VNC messages that would cause KVM to consume CPU
resources, leading to a denial of service. (CVE-2008-2382)
Jan Niehusmann discovered that KVM's Cirrus VGA implementation over
VNC did not correctly handle certain bitblt operations. A local
attacker could exploit this flaw to potentially execute arbitrary code
on the VM host or crash KVM, leading to a denial of service.
It was discovered that KVM's VNC password checks did not use the
correct length. A remote attacker could exploit this flaw to cause KVM
to crash, leading to a denial of service. (CVE-2008-5714).
Update the affected kvm and / or kvm-source packages.
Risk factor :
High / CVSS Base Score : 7.8