Bug#823830: qemu: CVE-2016-3710 CVE-2016-3712

2016-05-17 Thread Cristian Aires
thx On Tue, May 17, 2016 at 3:40 AM, Geert Stappers wrote: > On Mon, May 16, 2016 at 05:04:29PM -0300, Cristian Aires wrote: > > On Mon, 09 May 2016 14:22:37 +0200 Salvatore Bonaccorso wrote: > > > > > > For further information see: > > > > > > [0]

Bug#823830: qemu: CVE-2016-3710 CVE-2016-3712

2016-05-17 Thread Geert Stappers
On Mon, May 16, 2016 at 05:04:29PM -0300, Cristian Aires wrote: > On Mon, 09 May 2016 14:22:37 +0200 Salvatore Bonaccorso wrote: > > > > For further information see: > > > > [0] https://security-tracker.debian.org/tracker/CVE-2016-3710 > > [1]

Bug#823830: qemu: CVE-2016-3710 CVE-2016-3712

2016-05-16 Thread Cristian Aires
Hello, All types of video models are affected? The default is cirrus. On Mon, 09 May 2016 14:22:37 +0200 Salvatore Bonaccorso wrote: > Source: qemu > Version: 2.1+dfsg-1 > Severity: grave > Tags: security upstream > > Hi, > > the following vulnerabilities were published for

Bug#823830: qemu: CVE-2016-3710 CVE-2016-3712

2016-05-09 Thread Salvatore Bonaccorso
Source: qemu Version: 2.1+dfsg-1 Severity: grave Tags: security upstream Hi, the following vulnerabilities were published for qemu. CVE-2016-3710[0]: incorrect banked access bounds checking in vga module CVE-2016-3712[1]: Out-of-bounds read when creating weird vga screen surface If you fix