[ Marc Deslauriers ]
* SECURITY UPDATE: TOCTTOU in MTP
- debian/patches/CVE-2018-16872.patch: use O_NOFOLLOW and O_CLOEXEC in
hw/usb/dev-mtp.c.
- CVE-2018-16872
* SECURITY UPDATE: race during file renaming in v9fs_wstat
- debian/patches/CVE-2018-19489.patch: add locks to hw/9pfs/9p.c.
- CVE-2018-19489
* SECURITY UPDATE: out-of-bounds read via i2 commands
- debian/patches/CVE-2019-3812.patch: add bounds check to
hw/i2c/i2c-ddc.c.
- CVE-2019-3812
* SECURITY UPDATE: heap based buffer overflow in slirp
- debian/patches/CVE-2019-6778.patch: check data length while emulating
ident function in slirp/tcp_subr.c.
- CVE-2019-6778
[ Christian Ehrhardt ]
* fix crash when performing block pull on partial cluster (LP: #1818264)
- d/p/ubuntu/lp-1818264-block-Fix-copy-on-read-crash-with-partial.patch
* qemu-guest-agent: fix path of fsfreeze-hook (LP: #1820291)
- d/qemu-guest-agent.install: use correct path for fsfreeze-hook
- d/qemu-guest-agent.pre{rm|inst}/.postrm: special handling for
mv_conffile since the new path is a directory in the old package
version which can not be handled by mv_conffile
-- Marc Deslauriers <email address hidden> Mon, 25 Mar 2019 08:32:58 -0400
This bug was fixed in the package qemu - 1:2.11+ dfsg-1ubuntu7. 12
--------------- dfsg-1ubuntu7. 12) bionic-security; urgency=medium
qemu (1:2.11+
[ Marc Deslauriers ] patches/ CVE-2018- 16872.patch: use O_NOFOLLOW and O_CLOEXEC in usb/dev- mtp.c. patches/ CVE-2018- 19489.patch: add locks to hw/9pfs/9p.c. patches/ CVE-2019- 3812.patch: add bounds check to i2c/i2c- ddc.c. patches/ CVE-2019- 6778.patch: check data length while emulating
* SECURITY UPDATE: TOCTTOU in MTP
- debian/
hw/
- CVE-2018-16872
* SECURITY UPDATE: race during file renaming in v9fs_wstat
- debian/
- CVE-2018-19489
* SECURITY UPDATE: out-of-bounds read via i2 commands
- debian/
hw/
- CVE-2019-3812
* SECURITY UPDATE: heap based buffer overflow in slirp
- debian/
ident function in slirp/tcp_subr.c.
- CVE-2019-6778
[ Christian Ehrhardt ] lp-1818264- block-Fix- copy-on- read-crash- with-partial. patch guest-agent. install: use correct path for fsfreeze-hook guest-agent. pre{rm| inst}/. postrm: special handling for
* fix crash when performing block pull on partial cluster (LP: #1818264)
- d/p/ubuntu/
* qemu-guest-agent: fix path of fsfreeze-hook (LP: #1820291)
- d/qemu-
- d/qemu-
mv_conffile since the new path is a directory in the old package
version which can not be handled by mv_conffile
-- Marc Deslauriers <email address hidden> Mon, 25 Mar 2019 08:32:58 -0400