<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>176674</bug_id>
          
          <creation_ts>2007-05-01 12:34 0000</creation_ts>
          <short_desc>app-emulation/qemu Several vulnerabilities (CVE-2007-{132[0-3]|1366} )</short_desc>
          <delta_ts>2007-06-07 21:20:00 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://archives.neohapsis.com/archives/fulldisclosure/2007-05/0001.html</bug_file_loc>
          <status_whiteboard>B3 [noglsa] jaervosz</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>javier@miqueleiz.com</cc>
    
    <cc>lu_zero@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-01 12:34:46 0000</bug_when>
            <thetext>Debian Security Advisory DSA 1284-1 securitydebian.org 
 http://www.debian.org/security/ Moritz Muehlenhoff 
 May 1st, 2007 http://www.debian.org/security/faq 
 - -------------------------------------------------------------------------- 
 
Package : qemu 
 Vulnerability : several 
 Problem-Type : local 
 Debian-specific: no 
 CVE ID : CVE-2007-1320 CVE-2007-1321 CVE-2007-1322 CVE-2007-1323 CVE-2007-1366 
 
Several vulnerabilities have been discovered in the QEMU processor 
 emulator, which may lead to the execution of arbitrary code or denial of 
 service. The Common Vulnerabilities and Exposures project identifies the 
 following problems: 
 
CVE-2007-1320 
     Tavis Ormandy discovered that a memory management routine of the Cirrus 
     video driver performs insufficient bounds checking, which might 
     allow the execution of arbitrary code through a heap overflow. 
 
CVE-2007-1321 
     Tavis Ormandy discovered that the NE2000 network driver and the socket 
     code perform insufficient input validation, which might allow the 
     execution of arbitrary code through a heap overflow. 
 
CVE-2007-1322 
     Tavis Ormandy discovered that the &quot;icebp&quot; instruction can be abused to 
     terminate the emulation, resulting in denial of service. 
 
CVE-2007-1323 
     Tavis Ormandy discovered that the NE2000 network driver and the socket 
     code perform insufficient input validation, which might allow the 
     execution of arbitrary code through a heap overflow. 
 
CVE-2007-1366 
     Tavis Ormandy discovered that the &quot;aam&quot; instruction can be abused to 
     crash qemu through a division by zero, resulting in denial of 
     service. 
 
For the oldstable distribution (sarge) these problems have been fixed in 
 version 0.6.1+20050407-1sarge1. 
 
For the stable distribution (etch) these problems have been fixed 
 in version 0.8.2-4etch1. 
 
For the unstable distribution (sid) these problems will be fixed soon. 
 
We recommend that you upgrade your qemu packages.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-04 05:49:19 0000</bug_when>
            <thetext>*** Bug 176955 has been marked as a duplicate of this bug. ***</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-08 06:18:01 0000</bug_when>
            <thetext>lu_zero please advise and bump as necessary.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lu_zero@gentoo.org</who>
            <bug_when>2007-05-08 08:17:27 0000</bug_when>
            <thetext>qemu-0.9 is in portage, I&apos;d advise to use it since it has also major feature and performance improvements.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-08 09:47:01 0000</bug_when>
            <thetext>Thx Luca.

Arches please test and mark stable. Target keywords are:

qemu-0.9.0.ebuild:KEYWORDS=&quot;amd64 ppc x86&quot;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jokey@gentoo.org</who>
            <bug_when>2007-05-08 19:26:13 0000</bug_when>
            <thetext>Stable on x86</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-05-16 20:43:29 0000</bug_when>
            <thetext>@Luca: Can you handle the stabilization for ppc, please?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lu_zero@gentoo.org</who>
            <bug_when>2007-05-16 21:35:25 0000</bug_when>
            <thetext>ppc done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>fauli@gentoo.org</who>
            <bug_when>2007-05-20 08:31:33 0000</bug_when>
            <thetext>amd64 stable, last arch</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-05-20 10:25:45 0000</bug_when>
            <thetext>This one is ready for GLSA decision. I tend to vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>shellsage@gentoo.org</who>
            <bug_when>2007-05-20 15:34:41 0000</bug_when>
            <thetext>I vote no.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>py@gentoo.org</who>
            <bug_when>2007-05-31 09:27:10 0000</bug_when>
            <thetext>I tend to vote NO.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-06-01 15:08:29 0000</bug_when>
            <thetext>i vote Yes (buffer overflows -&gt; B2 or B1, i don&apos;t really understand why you have voted no)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2007-06-02 14:23:17 0000</bug_when>
            <thetext>I&apos;m not familiar with qemu. If they use the NE2000 and the Cirrus by default for virtualization I would vote yes. I assumed that you needed the hardware...</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-06-07 21:20:00 0000</bug_when>
            <thetext>Closing with [noglsa] since most of votes are No. Feel free to reopen if you disagree.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>