Public bug reported:

Binary package hint: kvm

kvm ships qemu 0.9.1 as part of its source code, and this version of
qemu is vulnerable to several CVEs.  Several of these were fixed in the
Debian DSA:

http://www.debian.org/security/2007/dsa-1284

This DSA fixes CVE-2007-1320, CVE-2007-1321, CVE-2007-1322, CVE-2007-1323.
Please note that CVE-2007-1323 is a duplicate of CVE-2007-2893.  Also note that 
CVE-2007-5729 and CVE-2007-5730 are referred to as CVE-2007-1321 in Debian.

In addition to these fixes, qemu 0.9.1 is also vulnerable to
CVE-2008-0928.

Will provide a debdiff soon.

** Affects: kvm (Ubuntu)
     Importance: High
     Assignee: Jamie Strandboge (jamie-strandboge)
         Status: Confirmed

** Affects: qemu (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: kvm (Ubuntu Dapper)
     Importance: Undecided
         Status: New

** Affects: qemu (Ubuntu Dapper)
     Importance: Undecided
         Status: New

** Affects: kvm (Ubuntu Edgy)
     Importance: Undecided
         Status: New

** Affects: qemu (Ubuntu Edgy)
     Importance: Undecided
         Status: New

** Affects: kvm (Ubuntu Feisty)
     Importance: Undecided
         Status: New

** Affects: qemu (Ubuntu Feisty)
     Importance: Undecided
         Status: New

** Affects: kvm (Ubuntu Gutsy)
     Importance: Undecided
         Status: New

** Affects: qemu (Ubuntu Gutsy)
     Importance: Undecided
         Status: New

** Changed in: kvm (Ubuntu)
   Importance: Undecided => High
     Assignee: (unassigned) => Jamie Strandboge (jamie-strandboge)
       Status: New => Confirmed

** Description changed:

  Binary package hint: kvm
  
- kvm uses qemu 0.9.1, and this version of qemu is vulnerable to several
- CVEs.  Several of these were fixed in the Debian DSA:
+ kvm ships qemu 0.9.1 as part of its source code, and this version of
+ qemu is vulnerable to several CVEs.  Several of these were fixed in the
+ Debian DSA:
  
  http://www.debian.org/security/2007/dsa-1284
  
  This DSA fixes CVE-2007-1320, CVE-2007-1321, CVE-2007-1322, CVE-2007-1323.
  Please note that CVE-2007-1323 is a duplicate of CVE-2007-2893.  Also note 
that CVE-2007-5729 and CVE-2007-5730 are referred to as CVE-2007-1321 in Debian.
  
  In addition to these fixes, qemu 0.9.1 is also vulnerable to
  CVE-2008-0928.
+ 
+ Will provide a debdiff soon.

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2007-1320

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2007-1321

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2007-1322

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2007-1366

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2007-2893

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-0928

** Also affects: qemu (Ubuntu)
   Importance: Undecided
       Status: New

-- 
kvm vulnerable to several CVEs
https://bugs.launchpad.net/bugs/213570
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to