Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 176674 - app-emulation/qemu Several vulnerabilities (CVE-2007-{132[0-3]|1366} )
Summary: app-emulation/qemu Several vulnerabilities (CVE-2007-{132[0-3]|1366} )
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://archives.neohapsis.com/archive...
Whiteboard: B3 [noglsa] jaervosz
Keywords:
: 176955 (view as bug list)
Depends on:
Blocks:
 
Reported: 2007-05-01 12:34 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2007-06-07 21:20 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-01 12:34:46 UTC
Debian Security Advisory DSA 1284-1 securitydebian.org 
 http://www.debian.org/security/ Moritz Muehlenhoff 
 May 1st, 2007 http://www.debian.org/security/faq 
 - -------------------------------------------------------------------------- 
 
Package : qemu 
 Vulnerability : several 
 Problem-Type : local 
 Debian-specific: no 
 CVE ID : CVE-2007-1320 CVE-2007-1321 CVE-2007-1322 CVE-2007-1323 CVE-2007-1366 
 
Several vulnerabilities have been discovered in the QEMU processor 
 emulator, which may lead to the execution of arbitrary code or denial of 
 service. The Common Vulnerabilities and Exposures project identifies the 
 following problems: 
 
CVE-2007-1320 
     Tavis Ormandy discovered that a memory management routine of the Cirrus 
     video driver performs insufficient bounds checking, which might 
     allow the execution of arbitrary code through a heap overflow. 
 
CVE-2007-1321 
     Tavis Ormandy discovered that the NE2000 network driver and the socket 
     code perform insufficient input validation, which might allow the 
     execution of arbitrary code through a heap overflow. 
 
CVE-2007-1322 
     Tavis Ormandy discovered that the "icebp" instruction can be abused to 
     terminate the emulation, resulting in denial of service. 
 
CVE-2007-1323 
     Tavis Ormandy discovered that the NE2000 network driver and the socket 
     code perform insufficient input validation, which might allow the 
     execution of arbitrary code through a heap overflow. 
 
CVE-2007-1366 
     Tavis Ormandy discovered that the "aam" instruction can be abused to 
     crash qemu through a division by zero, resulting in denial of 
     service. 
 
For the oldstable distribution (sarge) these problems have been fixed in 
 version 0.6.1+20050407-1sarge1. 
 
For the stable distribution (etch) these problems have been fixed 
 in version 0.8.2-4etch1. 
 
For the unstable distribution (sid) these problems will be fixed soon. 
 
We recommend that you upgrade your qemu packages.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-04 05:49:19 UTC
*** Bug 176955 has been marked as a duplicate of this bug. ***
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-08 06:18:01 UTC
lu_zero please advise and bump as necessary.
Comment 3 Luca Barbato gentoo-dev 2007-05-08 08:17:27 UTC
qemu-0.9 is in portage, I'd advise to use it since it has also major feature and performance improvements.
Comment 4 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-08 09:47:01 UTC
Thx Luca.

Arches please test and mark stable. Target keywords are:

qemu-0.9.0.ebuild:KEYWORDS="amd64 ppc x86"
Comment 5 Markus Ullmann (RETIRED) gentoo-dev 2007-05-08 19:26:13 UTC
Stable on x86
Comment 6 Tobias Scherbaum (RETIRED) gentoo-dev 2007-05-16 20:43:29 UTC
@Luca: Can you handle the stabilization for ppc, please?
Comment 7 Luca Barbato gentoo-dev 2007-05-16 21:35:25 UTC
ppc done
Comment 8 Christian Faulhammer (RETIRED) gentoo-dev 2007-05-20 08:31:33 UTC
amd64 stable, last arch
Comment 9 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-05-20 10:25:45 UTC
This one is ready for GLSA decision. I tend to vote NO.
Comment 10 Vic Fryzel (shellsage) (RETIRED) gentoo-dev 2007-05-20 15:34:41 UTC
I vote no.
Comment 11 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-05-31 09:27:10 UTC
I tend to vote NO.
Comment 12 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-06-01 15:08:29 UTC
i vote Yes (buffer overflows -> B2 or B1, i don't really understand why you have voted no)
Comment 13 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-06-02 14:23:17 UTC
I'm not familiar with qemu. If they use the NE2000 and the Cirrus by default for virtualization I would vote yes. I assumed that you needed the hardware...
Comment 14 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-06-07 21:20:00 UTC
Closing with [noglsa] since most of votes are No. Feel free to reopen if you disagree.