[Secure-testing-commits] r38805 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Sat Jan 9 14:12:37 UTC 2016


Author: carnil
Date: 2016-01-09 14:12:36 +0000 (Sat, 09 Jan 2016)
New Revision: 38805

Modified:
   data/CVE/list
Log:
Update information for CVE-2016-1568/qemu

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2016-01-09 14:02:59 UTC (rev 38804)
+++ data/CVE/list	2016-01-09 14:12:36 UTC (rev 38805)
@@ -1,10 +1,12 @@
 CVE-2016-1568 [ide: ahci use-after-free vulnerability in aio port commands]
 	- qemu <unfixed>
+	[squeeze] - qemu <not-affected> (Vulnerable code introduced later)
 	- qemu-kvm <removed>
-	NOTE: https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg01184.html
+	[squeeze] - qemu-kvm <not-affected> (Vulnerable code introduced later)
+	NOTE: Fixed by: https://lists.gnu.org/archive/html/qemu-devel/2016-01/msg01184.html
+	NOTE: ahci emulation added in: http://git.qemu.org/?p=qemu.git;a=commit;h=f6ad2e32f8d833c7f1c75dc084a84a8f02704d64 (v0.14.0-rc0)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=1288532
 	NOTE: http://www.openwall.com/lists/oss-security/2016/01/09/1
-	TODO: check versions
 CVE-2016-1563
 	RESERVED
 CVE-2016-1562




More information about the Secure-testing-commits mailing list