[ubuntu-cloud-archive/icehouse-proposed] qemu (Accepted)

James Page james.page at ubuntu.com
Tue Dec 15 15:33:42 UTC 2015


 qemu (2.0.0+dfsg-2ubuntu1.21~cloud0) precise-icehouse; urgency=medium
 .
   * New update for the Ubuntu Cloud Archive.
 .
 qemu (2.0.0+dfsg-2ubuntu1.21) trusty-security; urgency=medium
 .
   * SECURITY UPDATE: denial of service via jumbo frame flood in virtio
     - debian/patches/CVE-2015-7295.patch: drop truncated packets in
       hw/net/virtio-net.c, hw/virtio/virtio.c, include/hw/virtio/virtio.h.
     - CVE-2015-7295
   * SECURITY UPDATE: loopback mode heap overflow vulnerability in pcnet
     - debian/patches/CVE-2015-7504.patch: leave room for CRC code in
       hw/net/pcnet.c.
     - CVE-2015-7504
   * SECURITY UPDATE: non-loopback mode buffer overflow in pcnet
     - debian/patches/CVE-2015-7512.patch: check packet length in
       hw/net/pcnet.c.
     - CVE-2015-7512
   * SECURITY UPDATE: infinite loop in eepro100
     - debian/patches/CVE-2015-8345.patch: prevent endless loop in
       hw/net/eepro100.c.
     - CVE-2015-8345

Date: Fri, 04 Dec 2015 03:11:38 +0000
Changed-By: Openstack Ubuntu Testing Bot <openstack-testing-bot at ubuntu.com>
Signed-By: Openstack Ubuntu Testing Bot
Published-By: James Page <james.page at ubuntu.com>


More information about the Cloud-archive-changes mailing list