Bug#785689: I: Bug#785424: [Pkg-virtualbox-devel] Bug#785424: virtualbox: CVE-2015-3456: floppy driver host code execution

2015-05-19 Thread Gianfranco Costamagna
Package: virtualbox Severity: Serious Version: 4.3.18-dfsg-3 Tags: patch Virtualbox crashes after 10 minutes of run Il Lunedì 18 Maggio 2015 20:36, Frank Mehnert frank.mehn...@oracle.com ha scritto: Hi Gianfranco, could you also have a look here?

Bug#785424: [Pkg-virtualbox-devel] Bug#785424: virtualbox: CVE-2015-3456: floppy driver host code execution

2015-05-19 Thread Gianfranco Costamagna
Hi Frank, is 4.1.18 affected? cheers, Gianfranco Il Lunedì 18 Maggio 2015 20:36, Frank Mehnert frank.mehn...@oracle.com ha scritto: Hi Gianfranco, could you also have a look here? https://www.virtualbox.org/ticket/14128#comment:1 This is regarding the 4.3.18 Jessie package. Thanks,

Bug#785424: Re: Bug#785424: [Pkg-virtualbox-devel] Bug#785424: virtualbox: CVE-2015-3456: floppy driver host code execution

2015-05-19 Thread Gianfranco Costamagna
Hi Frank, yes I know, I wasn't sure if an update was needeed for wheezy too. I know the bug isn't related to the CVE, in fact I opened 785689 to track it down :) Unfortunately we will need to make another upload for it. cheers, Gianfranco Il Martedì 19 Maggio 2015 10:27, Frank Mehnert

Bug#785424: Re: Bug#785424: [Pkg-virtualbox-devel] Bug#785424: virtualbox: CVE-2015-3456: floppy driver host code execution

2015-05-19 Thread Frank Mehnert
Hi Gianfranco, ticket https://www.virtualbox.org/ticket/14128 is only about VBox version 4.3.18. No other version is affected by this bug. Note that this has nothing to do with CVE-2015-3456. Kind regards, Frank On Tuesday 19 May 2015 08:20:07 Gianfranco Costamagna wrote: Hi Frank, is 4.1.18

Bug#785424: virtualbox: CVE-2015-3456: floppy driver host code execution

2015-05-18 Thread Gianfranco Costamagna
Hi sid/testing: - 4.3.28 is not affected (upload pending) -jessie: 4.3.18-dfsg-3+deb8u2 is fixed in git branch jessie, with the upstream patch http://anonscm.debian.org/cgit/pkg-virtualbox/virtualbox.git/commit/?h=jessieid=990f846aec31871952b839ed93f7963f16bceb0c -wheezy: 4.1.18-dfsg-2+deb7u5

Bug#785424: [Pkg-virtualbox-devel] Bug#785424: virtualbox: CVE-2015-3456: floppy driver host code execution

2015-05-18 Thread Frank Mehnert
Hi Gianfranco, could you also have a look here? https://www.virtualbox.org/ticket/14128#comment:1 This is regarding the 4.3.18 Jessie package. Thanks, Frank On Monday 18 May 2015 16:48:13 Gianfranco Costamagna wrote: Hi sid/testing: - 4.3.28 is not affected (upload pending)

Bug#785424: virtualbox: CVE-2015-3456: floppy driver host code execution

2015-05-15 Thread Salvatore Bonaccorso
Source: virtualbox Version: 4.1.18-dfsg-1 Severity: grave Tags: security upstream fixed-upstream Justification: user security hole Hi, the following vulnerability was published for virtualbox. CVE-2015-3456[0]: | The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and | earlier and