[Secure-testing-commits] r49672 - data/CVE

Salvatore Bonaccorso carnil at moszumanska.debian.org
Tue Mar 14 12:32:37 UTC 2017


Author: carnil
Date: 2017-03-14 12:32:36 +0000 (Tue, 14 Mar 2017)
New Revision: 49672

Modified:
   data/CVE/list
Log:
Add CVE-2016-9603/qemu

Modified: data/CVE/list
===================================================================
--- data/CVE/list	2017-03-14 11:29:29 UTC (rev 49671)
+++ data/CVE/list	2017-03-14 12:32:36 UTC (rev 49672)
@@ -17017,8 +17017,14 @@
 	RESERVED
 CVE-2016-9604
 	RESERVED
-CVE-2016-9603
+CVE-2016-9603 [cirrus: heap buffer overflow via vnc connection]
 	RESERVED
+	- qemu <unfixed>
+	- qemu-kvm <removed>
+	- xen 4.4.0-1
+        NOTE: Xen switched to qemu-system in 4.4.0-1
+        NOTE: https://xenbits.xen.org/xsa/advisory-211.html
+	NOTE: http://www.openwall.com/lists/oss-security/2017/03/14/2
 CVE-2016-9602 [9p: virtfs allows guest to access host filesystem]
 	RESERVED
 	- qemu 1:2.8+dfsg-3 (bug #853006)




More information about the Secure-testing-commits mailing list