Accepted qemu 0.8.2-4etch1 (source i386)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Thu, 26 Apr 2007 07:36:40 +0300
Source: qemu
Binary: qemu
Architecture: source i386
Version: 0.8.2-4etch1
Distribution: stable-security
Urgency: high
Maintainer: Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org>
Changed-By: Guillem Jover <guillem@debian.org>
Description:
qemu - fast processor emulator
Changes:
qemu (0.8.2-4etch1) stable-security; urgency=high
.
[ Guillem Jover ]
* Fix several security issues found by Tavis Ormandy <taviso@google.com>:
- Cirrus LGD-54XX "bitblt" Heap Overflow. CVE-2007-1320
- NE2000 "mtu" heap overflow.
- QEMU "net socket" heap overflow.
- QEMU NE2000 "receive" integer signedness error. CVE-2007-1321
- Infinite loop in the emulated SB16 device.
- Unprivileged "aam" instruction does not correctly handle the
undocumented divisor operand. CVE-2007-1322
- Unprivileged "icebp" instruction will halt emulation. CVE-2007-1322
- debian/patches/90_security.patch: New file.
Files:
9d55f0fd6f5261bff1a83f6ea0652afb 1122 misc optional qemu_0.8.2-4etch1.dsc
312eebc1386cca2e9b30a40763ab9c0d 1501979 misc optional qemu_0.8.2.orig.tar.gz
e4f93234058f38d4fffbacb9524bbaa4 63407 misc optional qemu_0.8.2-4etch1.diff.gz
20e6e9eb0ea92b043397e3ea348a3925 3675760 misc optional qemu_0.8.2-4etch1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGMD2GuW9ciZ2SjJsRAuzeAJ9m9U+KxCB2VHJpDV0czE5fkMh+8QCgo6ZB
+XcpvUSY6Q3LA3n8DJsLg/8=
=lqRF
-----END PGP SIGNATURE-----
Accepted:
qemu_0.8.2-4etch1.diff.gz
to pool/main/q/qemu/qemu_0.8.2-4etch1.diff.gz
qemu_0.8.2-4etch1.dsc
to pool/main/q/qemu/qemu_0.8.2-4etch1.dsc
qemu_0.8.2-4etch1_i386.deb
to pool/main/q/qemu/qemu_0.8.2-4etch1_i386.deb
Reply to: