First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 176674
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 176674 depends on: Show dependency tree
Bug 176674 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-05-01 12:34 0000
Debian Security Advisory DSA 1284-1 securitydebian.org 
 http://www.debian.org/security/ Moritz Muehlenhoff 
 May 1st, 2007 http://www.debian.org/security/faq 
 - -------------------------------------------------------------------------- 

Package : qemu 
 Vulnerability : several 
 Problem-Type : local 
 Debian-specific: no 
 CVE ID : CVE-2007-1320 CVE-2007-1321 CVE-2007-1322 CVE-2007-1323 CVE-2007-1366 

Several vulnerabilities have been discovered in the QEMU processor 
 emulator, which may lead to the execution of arbitrary code or denial of 
 service. The Common Vulnerabilities and Exposures project identifies the 
 following problems: 

CVE-2007-1320 
     Tavis Ormandy discovered that a memory management routine of the Cirrus 
     video driver performs insufficient bounds checking, which might 
     allow the execution of arbitrary code through a heap overflow. 

CVE-2007-1321 
     Tavis Ormandy discovered that the NE2000 network driver and the socket 
     code perform insufficient input validation, which might allow the 
     execution of arbitrary code through a heap overflow. 

CVE-2007-1322 
     Tavis Ormandy discovered that the "icebp" instruction can be abused to 
     terminate the emulation, resulting in denial of service. 

CVE-2007-1323 
     Tavis Ormandy discovered that the NE2000 network driver and the socket 
     code perform insufficient input validation, which might allow the 
     execution of arbitrary code through a heap overflow. 

CVE-2007-1366 
     Tavis Ormandy discovered that the "aam" instruction can be abused to 
     crash qemu through a division by zero, resulting in denial of 
     service. 

For the oldstable distribution (sarge) these problems have been fixed in 
 version 0.6.1+20050407-1sarge1. 

For the stable distribution (etch) these problems have been fixed 
 in version 0.8.2-4etch1. 

For the unstable distribution (sid) these problems will be fixed soon. 

We recommend that you upgrade your qemu packages.

------- Comment #1 From Sune Kloppenborg Jeppesen 2007-05-04 05:49:19 0000 -------
*** Bug 176955 has been marked as a duplicate of this bug. ***

------- Comment #2 From Sune Kloppenborg Jeppesen 2007-05-08 06:18:01 0000 -------
lu_zero please advise and bump as necessary.

------- Comment #3 From Luca Barbato 2007-05-08 08:17:27 0000 -------
qemu-0.9 is in portage, I'd advise to use it since it has also major feature
and performance improvements.

------- Comment #4 From Sune Kloppenborg Jeppesen 2007-05-08 09:47:01 0000 -------
Thx Luca.

Arches please test and mark stable. Target keywords are:

qemu-0.9.0.ebuild:KEYWORDS="amd64 ppc x86"

------- Comment #5 From Markus Ullmann 2007-05-08 19:26:13 0000 -------
Stable on x86

------- Comment #6 From Tobias Scherbaum 2007-05-16 20:43:29 0000 -------
@Luca: Can you handle the stabilization for ppc, please?

------- Comment #7 From Luca Barbato 2007-05-16 21:35:25 0000 -------
ppc done

------- Comment #8 From Christian Faulhammer 2007-05-20 08:31:33 0000 -------
amd64 stable, last arch

------- Comment #9 From Sune Kloppenborg Jeppesen 2007-05-20 10:25:45 0000 -------
This one is ready for GLSA decision. I tend to vote NO.

------- Comment #10 From Vic Fryzel (shellsage) (RETIRED) 2007-05-20 15:34:41 0000 -------
I vote no.

------- Comment #11 From Pierre-Yves Rofes 2007-05-31 09:27:10 0000 -------
I tend to vote NO.

------- Comment #12 From Raphael Marichez 2007-06-01 15:08:29 0000 -------
i vote Yes (buffer overflows -> B2 or B1, i don't really understand why you
have voted no)

------- Comment #13 From Sune Kloppenborg Jeppesen 2007-06-02 14:23:17 0000 -------
I'm not familiar with qemu. If they use the NE2000 and the Cirrus by default
for virtualization I would vote yes. I assumed that you needed the hardware...

------- Comment #14 From Raphael Marichez 2007-06-07 21:20:00 0000 -------
Closing with [noglsa] since most of votes are No. Feel free to reopen if you
disagree.

First Last Prev Next    No search results available      Search page      Enter new bug