[PVE-User] Venom exploit?

Steffen Wagner mail at steffenwagner.com
Fri May 15 10:40:57 CEST 2015


Is there a workaround or bugfix in sight?

Thanks,
Steffen

-- 
Steffen Wagner 
August-Bebel-Straße 61 
D-68199 Mannheim 

M +49 (0) 1523 3544688 
E mail at steffenwagner.com 
I http://wagnst.de 

Get my public GnuPG key: 
mail <at> steffenwagner <dot> com 
http://http-keys.gnupg.net/pks/lookup?op=get&search=0x8A3406FB4688EE99 

Am 15.05.2015 09:41 schrieb Alexandre DERUMIER <aderumier at odiso.com>:
>
> >>Does this bug affects Proxmox ?
> yes, any qemu is affected.
>
> >> As far as I'm aware, there's no option to add Floppy device to the VMs, not through the GUI at least.
> It's not about floppy device, it's about floppy controller, which is embedded in virtual qemu motherboard (and can't be removed).
>
> So that's why is affected any qemu version, floppy device or not.
>
> ----- Mail original -----
> De: "Iosif Peterfi" <iosif.peterfi at gmail.com>
> À: "proxmoxve" <pve-user at pve.proxmox.com>
> Envoyé: Jeudi 14 Mai 2015 07:39:51
> Objet: Re: [PVE-User] Venom exploit?
>
> Does this bug affects Proxmox ? As far as I'm aware, there's no option to add Floppy device to the VMs, not through the GUI at least.
>
> On Wed, May 13, 2015 at 11:35 PM, Laurent Dumont < admin at coldnorthadmin.com > wrote: 
>
> You have to love the names they come up for CVE's now. I guess marketing really works after all.
>
> There seem to be a patch in the works for pve.
>
> http://pve.proxmox.com/pipermail/pve-devel/2015-May/015123.html 
>
> On 5/13/2015 4:14 PM, Paul Gray wrote:
>
> BQ_BEGIN
> http://arstechnica.com/security/2015/05/extremely-serious-virtual-machine-bug-threatens-cloud-providers-everywhere/
>
> Apologies if this has been touched upon elsewhere, but has this been 
> addressed?
>
> -PG 
> _______________________________________________ 
> pve-user mailing list 
> pve-user at pve.proxmox.com 
> http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-user 
>
> -- 
> Laurent Dumont 
> coldnorthadmin.com 
>
> _______________________________________________ 
> pve-user mailing list 
> pve-user at pve.proxmox.com 
> http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-user
>
> BQ_END
>
> _______________________________________________ 
> pve-user mailing list 
> pve-user at pve.proxmox.com 
> http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-user
>
> _______________________________________________
> pve-user mailing list
> pve-user at pve.proxmox.com
> http://pve.proxmox.com/cgi-bin/mailman/listinfo/pve-user


More information about the pve-user mailing list