Your message dated Fri, 1 Mar 2013 17:53:13 +0100 with message-id <20130301165313.GE12259@inutil.org> and subject line Re: Bug#699396: CVE-2013-0241 - qxl: synchronous io guest DoS has caused the Debian Bug report #699396, regarding CVE-2013-0241 - qxl: synchronous io guest DoS to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact owner@bugs.debian.org immediately.) -- 699396: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699396 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
--- Begin Message ---
- To: submit@bugs.debian.org
- Subject: CVE-2013-0241 - qxl: synchronous io guest DoS
- From: Luciano Bello <luciano@debian.org>
- Date: Thu, 31 Jan 2013 00:10:16 +0100
- Message-id: <201301310010.16680.luciano@debian.org>
Package: xserver-xorg-video-qxl Severity: grave Tags: security patch Justification: user security hole Hi there, Take a look to http://seclists.org/oss-sec/2013/q1/204 Please, use CVE-2013-0241 to refer this issue. The Debian package in unstable looks affected. Can you check if the stable or testings are affected too? Cheers, luciano
--- End Message ---
--- Begin Message ---
- To: Liang Guo <bluestonechina@gmail.com>
- Cc: 699396-done@bugs.debian.org
- Subject: Re: Bug#699396: CVE-2013-0241 - qxl: synchronous io guest DoS
- From: Moritz Muehlenhoff <jmm@inutil.org>
- Date: Fri, 1 Mar 2013 17:53:13 +0100
- Message-id: <20130301165313.GE12259@inutil.org>
- In-reply-to: <20130131165702.GA9903@blueice2>
- References: <201301310010.16680.luciano@debian.org> <20130131165702.GA9903@blueice2>
Version: 0.0.17-1 On Fri, Feb 01, 2013 at 12:57:02AM +0800, Liang Guo wrote: > Hi, > > On Thu, Jan 31, 2013 at 12:10:16AM +0100, Luciano Bello wrote: > > Package: xserver-xorg-video-qxl > > Severity: grave > > Tags: security patch > > Justification: user security hole > > > > Hi there, > > Take a look to http://seclists.org/oss-sec/2013/q1/204 > > Please, use CVE-2013-0241 to refer this issue. > > The Debian package in unstable looks affected. Can you check if the stable or > > testings are affected too? > > > > Cheers, > > luciano > Would you like to check xserver-xorg-video-qxl 0.0.17 is > affected? > > According to http://seclists.org/oss-sec/2013/q1/204, this > bug is fixed in commit 30b4b72cdbdf9f0e92a8d1c4e01779f60f15a741, > which is included in 0.0.17. Closing the bug properly. Cheers, Moritz
--- End Message ---