Qemu version pin vulnerable to VENOM

Bug #1454677 reported by Christopher H. Laco
264
This bug affects 2 people
Affects Status Importance Assigned to Milestone
OpenStack-Ansible
Invalid
Critical
Unassigned
Icehouse
Won't Fix
Critical
Unassigned
Juno
Won't Fix
Critical
Unassigned

CVE References

tags: added: icehouse-backport-potential impacts-doc juno-backport-potential
description: updated
description: updated
Revision history for this message
Kevin Carter (kevin-carter) wrote :

While the issue of the qemu package effects all of Ubuntu 14.04 the issue due to package pinning does not effect trunk and kilo as such trunk has been marked as invalid.

no longer affects: openstack-ansible/trunk
Changed in openstack-ansible:
status: New → Invalid
description: updated
description: updated
description: updated
Revision history for this message
George Shuklin (george-shuklin) wrote :

Can someone explain how it can affect openstack installation? I don't see any 'virtual floppy' device inside guest machines.

Revision history for this message
Ian Cordasco (icordasc) wrote :

George, please see the discussion on the openstack-operators mailing list: http://lists.openstack.org/pipermail/openstack-operators/2015-May/006945.html

Revision history for this message
Jimmy McCrory (jimmy-mccrory) wrote :
Revision history for this message
Christopher H. Laco (claco) wrote :

Jimmy, I filed this as it happened so people would at least dig in further. I very well may be the case now that this barely effects anything, except as you've noticed, the repo config file you have linked to.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.