{"id":997,"date":"2015-05-15T01:24:50","date_gmt":"2015-05-15T01:24:50","guid":{"rendered":"http:\/\/www.pir8geek.com\/?p=997"},"modified":"2015-05-15T01:24:50","modified_gmt":"2015-05-15T01:24:50","slug":"how-to-patch-venom-vulnerability-cve-2015-3456-on-linux","status":"publish","type":"post","link":"https:\/\/www.jameseduard.com\/?p=997","title":{"rendered":"How to Patch  VENOM Vulnerability  [CVE-2015-3456] on Linux"},"content":{"rendered":"<p>Recently a new vulnerability known as <strong>VENOM<\/strong> discover by <em><strong>Jason GeFFner<\/strong><\/em> \u00a0a buffer overflow vulnerability affecting the <em>Floppy Disk Controller emulation<\/em> and this bug <em>FDC<\/em> mostly affected are virtualization platforms and applications including <em>KVM,, Virtualbox ,Xen and\u00a0native QEMU client<\/em><br \/>\n<strong>What is the VENOM security bug (CVE-2015-3456)?<\/strong><br \/>\nAn out-of-bounds memory access flaw was found in the way QEMU&#8217;s virtual Floppy Disk Controller (FDC) handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the hosting QEMU process.<br \/>\n<strong>How was the Venom vulnerability discovered?<\/strong><br \/>\nJason Geffner, CrowdStrike Senior Security Researcher, discovered the vulnerability while performing a security review of virtual machine hypervisors.\u00a0After verifying the vulnerability, CrowdStrike responsibly disclosed VENOM to the QEMU Security Contact List, Xen Security mailing list, Oracle security mailing list, and the Operating System Distribution Security mailing list on April 30, 2015.<br \/>\n<strong>A list of affected Linux distrobutions:<\/strong><br \/>\n<strong>Ubuntu:<\/strong><\/p>\n<ul>\n<li>Ubuntu (vivid)<\/li>\n<li>Ubuntu 14.10<\/li>\n<li>Ubuntu 14.04 LTS<\/li>\n<li>Ubuntu 12.04 LTS<\/li>\n<\/ul>\n<p><strong>Redhat<\/strong><\/p>\n<ul>\n<li>RHEL (Red Hat Enterprise Linux) version 5.x, 6.x and 7.x<\/li>\n<li>CentOS Linux version 5.x, 6.x and 7.x<\/li>\n<li>OpenStack 5 for RHEL 6<\/li>\n<li>OpenStack 4 for RHEL 6<\/li>\n<li>OpenStack 5 for RHEL 7<\/li>\n<li>OpenStack 6 for RHEL 7<\/li>\n<li>Red Hat Enterprise Virtualization 3<\/li>\n<\/ul>\n<p><strong>Debian:<\/strong><\/p>\n<ul>\n<li>Debian Linux code named stretch, sid, jessie, squeeze, and wheezy [and all other distro based on Debian]<\/li>\n<\/ul>\n<p><strong>Suse\u00a0Linux:<\/strong><\/p>\n<ul>\n<li>SUSE Linux Enterprise Server 10 Service Pack 4 (SLES 10 SP3)<\/li>\n<li>SUSE Linux Enterprise Server 10 Service Pack 4 (SLES 10 SP4)<\/li>\n<li>SUSE Linux Enterprise Server 11 Service Pack 1 (SLES 11 SP1)<\/li>\n<li>SUSE Linux Enterprise Server 11 Service Pack 2 (SLES 11 SP2)<\/li>\n<li>SUSE Linux Enterprise Server 11 Service Pack 3 (SLES 11 SP3)<\/li>\n<li>SUSE Linux Enterprise Server 12<\/li>\n<li>SUSE Linux Enterprise Expanded Support 5, 6 and 7<\/li>\n<\/ul>\n<p>&nbsp;<br \/>\n1. To patch VENOM Vulnerability on Ubuntu Linux, Open a terminal and type the following command as a root user.<\/p>\n<pre>sudo apt-get clean\nsudo apt-get update\nsudo apt-get upgrade\n<\/pre>\n<p>After applying updates, reboot your virtual machines or system.<br \/>\n2. To patch VENOM Vulnerability on Debian Linux, Open a terminal and type the following command as a root user.<\/p>\n<pre>sudo apt-get clean\nsudo apt-get update\nsudo apt-get upgrade\n<\/pre>\n<p>3.To patch VENOM Vulnerability on CentOS\/RHEL and Fedora\u00a0Linux, Open a terminal and type the following command as a root user.<\/p>\n<pre>\nsudo yum clean all\nsudo yum update\n<\/pre>\n<p>Then reboot the virtual machines.<br \/>\n4. After applying updates, reboot your virtual machines or hypervisor.<br \/>\nFor more info about Venom bug:<\/p>\n<ul>\n<li><a href=\"http:\/\/venom.crowdstrike.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">CrowdStrike\u00a0<\/a><\/li>\n<li><a href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2015-3456\" target=\"_blank\" rel=\"noopener noreferrer\">Debian Linux security tracker<\/a><\/li>\n<li><a href=\"https:\/\/access.redhat.com\/security\/cve\/CVE-2015-3456\" target=\"_blank\" rel=\"noopener noreferrer\">RHEL Security\u00a0<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Recently a new vulnerability known as VENOM discover by Jason GeFFner \u00a0a buffer overflow vulnerability affecting the Floppy Disk Controller emulation and this bug FDC mostly affected are virtualization platforms and applications including KVM,, Virtualbox ,Xen and\u00a0native QEMU client What is the VENOM security bug (CVE-2015-3456)? An out-of-bounds memory access flaw was found in the<\/p>\n","protected":false},"author":1,"featured_media":1005,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[417,431],"tags":[424,448,449,450],"class_list":["post-997","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-virtualization","category-vulnerability-analysis","tag-blogs","tag-cve-2015-3456","tag-patches","tag-venom-vulnerability"],"_links":{"self":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts\/997","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=997"}],"version-history":[{"count":0,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=\/wp\/v2\/posts\/997\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=997"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=997"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jameseduard.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=997"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}