Lucene search

K
osvGoogleOSV:DSA-1799-1
HistoryMay 11, 2009 - 12:00 a.m.

qemu - several vulnerabilities

2009-05-1100:00:00
Google
osv.dev
9

0.001 Low

EPSS

Percentile

28.7%

Several vulnerabilities have been discovered in the QEMU processor
emulator. The Common Vulnerabilities and Exposures project identifies the
following problems:

  • CVE-2008-0928
    Ian Jackson discovered that range checks of file operations on
    emulated disk devices were insufficiently enforced.
  • CVE-2008-1945
    It was discovered that an error in the format auto detection of
    removable media could lead to the disclosure of files in the
    host system.
  • CVE-2008-4539
    A buffer overflow has been found in the emulation of the Cirrus
    graphics adaptor.

For the old stable distribution (etch), these problems have been fixed in
version 0.8.2-4etch3.

For the stable distribution (lenny), these problems have been fixed in
version 0.9.1-10lenny1.

For the unstable distribution (sid), these problems have been fixed in
version 0.9.1+svn20081101-1.

We recommend that you upgrade your qemu packages.

CPENameOperatorVersion
qemueq0.9.1-10
qemueq0.9.1-10lenny1~bpo40+1