• [SECURITY] [DSA 2909-1] qemu security update

    From Salvatore Bonaccorso@1:229/2 to All on Fri Apr 18 08:40:01 2014
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2909-1 [email protected] http://www.debian.org/security/ Salvatore Bonaccorso
    April 18, 2014 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : qemu
    CVE ID : CVE-2014-0150
    Debian Bug : 744221

    Michael S. Tsirkin of Red Hat discovered a buffer overflow flaw in the
    way qemu processed MAC addresses table update requests from the guest.

    A privileged guest user could use this flaw to corrupt qemu process
    memory on the host, which could potentially result in arbitrary code
    execution on the host with the privileges of the qemu process.

    For the oldstable distribution (squeeze), this problem has been fixed in version 0.12.5+dfsg-3squeeze4.

    For the stable distribution (wheezy), this problem has been fixed in
    version 1.1.2+dfsg-6a+deb7u1.

    For the testing distribution (jessie), this problem has been fixed in
    version 1.7.0+dfsg-8.

    For the unstable distribution (sid), this problem has been fixed in
    version 1.7.0+dfsg-8.

    We recommend that you upgrade your qemu packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBCgAGBQJTUMceAAoJEAVMuPMTQ89ER1MP/2u7L5p57jd00nMGz3Hj1QAG ZGQaunTpkvm6qasUSPfMzI3PyQHCErFg9Bs7nsj4AQMcZER/67TaE8qWn96eHO/S YSJum00wyzSlKGkwhFnvc8GbcTKyky3g59mS30z0Zzwj0Ogc6wWGb0CYJBuCQFcr u27RlC3Skdm+CgHBXrW5gsPGZXR4yfHcJctNA5nDoCyR9RKr+xtn9rOzO0aJN585 piACeK/rXHnlkztSVp+pROy1NhSxq1c5oYPJ/eLT7kfK7sHw/FDnzEARCz7DXrV+ NNpprH7K31336FtpSz1iBuwHuuIw8e92wHarMrA3gLGU+eTZLqEyG6jaNqHwV5K7 NQyN76MAL1XMr09Kb4rKIYAMPIZsUBDc9PGKoriI7S7g2wgOvSnr45IpAtl/WpCv GVSqsA+JVbil15vWEiOVVFLvaCIYxsW+fadU5EI5z3vrMgjXrlurHbGzoXgP44V6 3JfRi9EDI0Zs3/A4Y5DIpXRGslEcHdhZuzB0kRmZzU871+EHnmvayDduz0r6+grD RSXaqeMyiEt8lMnK9k5cx2AZrlOPMEC4EuRR7K/j6nr/l6+4u1xiQq6SVZNua1At yDxiFY6Jkkd9QRYr5VL/lowjHdTC7nFvj/56ZFpEMRB4wtCOv0LpC1rgjHnE2iTS RfaFtODKuUNyp8p7EyU5
    =HXIq
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)