lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20200202204701.6pp72g57xvjxgjmr@seger.debian.org> Date: Sun, 2 Feb 2020 20:47:01 +0000 From: Moritz Muehlenhoff <jmm@...ian.org> To: bugtraq@...urityfocus.com Subject: [SECURITY] [DSA 4616-1] qemu security update -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4616-1 security@...ian.org https://www.debian.org/security/ Moritz Muehlenhoff February 02, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : qemu CVE ID : CVE-2019-15890 CVE-2020-7039 CVE-2020-1711 Two security issues have been found in the SLiRP networking implementation of QEMU, a fast processor emulator, which could result in the execution of arbitrary code or denial of service. For the oldstable distribution (stretch), these problems have been fixed in version 1:2.8+dfsg-6+deb9u9. For the stable distribution (buster), these problems have been fixed in version 1:3.1+dfsg-8+deb10u4. We recommend that you upgrade your qemu packages. For the detailed security status of qemu please refer to its security tracker page at: https://security-tracker.debian.org/tracker/qemu Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@...ts.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl43NDEACgkQEMKTtsN8 Tjb57g/+L9/UOFkF6nb1TzwnP2Qp8TgNxOjHc4PFwEZ694hYFwdVP+CVD7DA3sML Rid0KgD3cEUhawZRGZakb/OZT9xRxzKWWjg6sXwA5k36zAF7qS2EW68kU9+5VOCU MaMm1LEZepcueRPCcD7jVVaZID5QODZuBSXPPNxAvELkCYg/dJU+kf4omYHNFSv0 83CavqqK6cg7N12/fJfIvldBSEc6dHC1WTOsZcLwY2Q7iBOY/790KucXeJKdrikS 3MjooF7hbemI6/XWrlH82NX9y3c4ThF50tJaTnoLJijOQPRF4S61IA81VdYojZVY uqViqPMqy37tpMHLe2x505tPPa4hGykZ0mN2yM4/6PdXtqndnrpG456WITsaZN7t iH9JZbkTxs5wR6pLjFx6l7gXwWH9AzpUxBBQgwFNsWcna66uuSHAhIfK141PERCl mqkXEOjq1j/23Bpd530n5siPr3gctu5hwemzT0EATS7QU7b0JOQeslsl52D3Tvh2 gpUkH9ht5g8x3zT9y7BATSlxGKAbOZvp/tVGRqa8DJtlelcACGOet1LBFgKC3W8J l+zRWI4q2+5EIMB3PPTkuxdegrEzffUZoK5W2+oWrmdTdWTBnmfNyedSzDWRtJ1O Qd8cHp3jAH3mkGX3Ct+yOYRHsqW4GL6IO3FWbzZsAOwkEVjA18Q= =vu2H -----END PGP SIGNATURE-----
Powered by blists - more mailing lists