Dmitry E. Oboukhov discovered that the qemu-make-debian-root script in qemu,
fast processor emulator, creates temporary files insecurely, which may lead
to a local denial of service through symlink attacks.
For the stable distribution (etch), this problem has been fixed in
version 0.8.2-4etch2.
For the testing (lenny) and unstable distribution (sid), this problem has
been fixed in version 0.9.1-6.
We recommend that you upgrade your qemu package.
CPE | Name | Operator | Version |
---|---|---|---|
qemu | eq | 0.8.2-4etch1 | |
qemu | eq | 0.8.2-4 |