[Secure-testing-commits] r38808 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Sat Jan 9 18:55:06 UTC 2016
Author: carnil
Date: 2016-01-09 18:55:06 +0000 (Sat, 09 Jan 2016)
New Revision: 38808
Modified:
data/CVE/list
Log:
Four CVEs addressed in qemu upload to unstable
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2016-01-09 15:19:41 UTC (rev 38807)
+++ data/CVE/list 2016-01-09 18:55:06 UTC (rev 38808)
@@ -1,5 +1,5 @@
CVE-2016-1568 [ide: ahci use-after-free vulnerability in aio port commands]
- - qemu <unfixed> (bug #810527)
+ - qemu 1:2.5+dfsg-2 (bug #810527)
[squeeze] - qemu <not-affected> (Vulnerable code introduced later)
- qemu-kvm <removed>
[squeeze] - qemu-kvm <not-affected> (Vulnerable code introduced later)
@@ -884,7 +884,7 @@
NOTE: VMXNET3 device implementation introduced in http://git.qemu.org/?p=qemu.git;a=commit;h=786fd2b0f87baded8c9e55307b99719eea3e016e (v1.5.0-rc0)
CVE-2015-8743 [net: ne2000: OOB r/w in ioport operations]
RESERVED
- - qemu <unfixed> (bug #810519)
+ - qemu 1:2.5+dfsg-2 (bug #810519)
[squeeze] - qemu <end-of-life> (Unsupported in squeeze-lts)
- qemu-kvm <removed>
[squeeze] - qemu-kvm <end-of-life> (Unsupported in squeeze-lts)
@@ -2573,7 +2573,7 @@
- linux 4.3.3-3
- linux-2.6 <removed>
[squeeze] - linux-2.6 <no-dsa> (Xen not supported in Squeeze LTS)
- - qemu <unfixed> (bug #809229)
+ - qemu 1:2.5+dfsg-2 (bug #809229)
[squeeze] - qemu <end-of-life> (Unsupported in Squeeze LTS)
- qemu-kvm <removed>
[squeeze] - qemu-kvm <end-of-life> (Not supported in Squeeze LTS)
@@ -2625,7 +2625,7 @@
NOTE: Workaround: use validatorless bootstrapping
CVE-2015-8558 [usb: infinite loop in ehci_advance_state results in DoS]
RESERVED
- - qemu <unfixed> (bug #808144)
+ - qemu 1:2.5+dfsg-2 (bug #808144)
[squeeze] - qemu <end-of-life> (Not supported in Squeeze LTS)
- qemu-kvm <removed>
[squeeze] - qemu-kvm <end-of-life> (Not supported in Squeeze LTS)
More information about the Secure-testing-commits
mailing list