CVE-2014-3689: insufficient parameter validation in vmware_vga rectangle functions

Related Vulnerabilities: CVE-2014-3689   CVE-2014-3615   CVE-2014-7815  

Debian Bug report logs - #765496
CVE-2014-3689: insufficient parameter validation in vmware_vga rectangle functions

version graph

Reported by: Michael Tokarev <mjt@tls.msk.ru>

Date: Wed, 15 Oct 2014 16:21:02 UTC

Severity: normal

Tags: patch, security, upstream

Found in version qemu/2.1+dfsg-5

Fixed in versions qemu/2.1+dfsg-6, qemu-kvm/1.1.2+dfsg-6+deb7u5, qemu/1.1.2+dfsg-6a+deb7u5

Done: Michael Tokarev <mjt@tls.msk.ru>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, mjt@tls.msk.ru, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org>:
Bug#765496; Package qemu-system-x86. (Wed, 15 Oct 2014 16:21:06 GMT) (full text, mbox, link).


Acknowledgement sent to Michael Tokarev <mjt@tls.msk.ru>:
New Bug report received and forwarded. Copy sent to mjt@tls.msk.ru, team@security.debian.org, secure-testing-team@lists.alioth.debian.org, Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org>. (Wed, 15 Oct 2014 16:21:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Michael Tokarev <mjt@tls.msk.ru>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2014-3689: insufficient parameter validation in vmware_vga rectangle functions
Date: Wed, 15 Oct 2014 18:17:53 +0200
Package: qemu-system-x86
Version: 2.1+dfsg-5
Severity: normal
Tags: security upstream patch

CVE-2014-3689 has been reported agaist qemu vmware-vga device.

I think the priority of this isn't high because the device
isn't used widely, if not only for compatibility for "upgrading"
from vmware host.  Yet still, some people might be using it
thinking it is more efficient than other options.

Upstream fix, thread:

 http://thread.gmane.org/gmane.comp.emulators.qemu/301713

/mjt



Added tag(s) pending. Request was from <mjt@tls.msk.ru> to control@bugs.debian.org. (Mon, 03 Nov 2014 09:45:10 GMT) (full text, mbox, link).


Reply sent to Michael Tokarev <mjt@tls.msk.ru>:
You have taken responsibility. (Mon, 03 Nov 2014 15:39:39 GMT) (full text, mbox, link).


Notification sent to Michael Tokarev <mjt@tls.msk.ru>:
Bug acknowledged by developer. (Mon, 03 Nov 2014 15:39:39 GMT) (full text, mbox, link).


Message #12 received at 765496-close@bugs.debian.org (full text, mbox, reply):

From: Michael Tokarev <mjt@tls.msk.ru>
To: 765496-close@bugs.debian.org
Subject: Bug#765496: fixed in qemu 2.1+dfsg-6
Date: Mon, 03 Nov 2014 15:34:49 +0000
Source: qemu
Source-Version: 2.1+dfsg-6

We believe that the bug you reported is fixed in the latest version of
qemu, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 765496@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Tokarev <mjt@tls.msk.ru> (supplier of updated qemu package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 03 Nov 2014 18:07:48 +0300
Source: qemu
Binary: qemu qemu-system qemu-system-common qemu-system-misc qemu-system-arm qemu-system-mips qemu-system-ppc qemu-system-sparc qemu-system-x86 qemu-user qemu-user-static qemu-user-binfmt qemu-utils qemu-guest-agent qemu-kvm
Architecture: source amd64
Version: 2.1+dfsg-6
Distribution: unstable
Urgency: medium
Maintainer: Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Description:
 qemu       - fast processor emulator
 qemu-guest-agent - Guest-side qemu-system agent
 qemu-kvm   - QEMU Full virtualization on x86 hardware
 qemu-system - QEMU full system emulation binaries
 qemu-system-arm - QEMU full system emulation binaries (arm)
 qemu-system-common - QEMU full system emulation binaries (common files)
 qemu-system-mips - QEMU full system emulation binaries (mips)
 qemu-system-misc - QEMU full system emulation binaries (miscelaneous)
 qemu-system-ppc - QEMU full system emulation binaries (ppc)
 qemu-system-sparc - QEMU full system emulation binaries (sparc)
 qemu-system-x86 - QEMU full system emulation binaries (x86)
 qemu-user  - QEMU user mode emulation binaries
 qemu-user-binfmt - QEMU user mode binfmt registration for qemu-user
 qemu-user-static - QEMU user mode emulation binaries (static version)
 qemu-utils - QEMU utilities
Closes: 747636 755740 760949 765075 765496
Changes:
 qemu (2.1+dfsg-6) unstable; urgency=medium
 .
   * mention closing of CVE-2014-3615 by 2.1.2 (2.1+dfsg-5)
   * 9p-use-little-endian-format-for-xattr-values.patch (Closes: #755740)
   * mention closing of #760386
   * mention closing of more CVEs by 2.1+dfsg-1
   * recognize ppc64el in qemu-debootstrap (Luca Falavigna) (Closes: #760949)
   * use dpkg-vendor to let derived distros to use our d/rules
   * use /usr/share/dpkg/architecture.mk to get DEB_HOST_* and DEB_BUILD_*
     variables.  This restores cross building support.
   * use /usr/share/dpkg/buildflags.mk for CFLAGS LDFLAGS &Co
   * pass -DVENDOR_{DEBIAN,UBUNTU} to compiler
   * do not treat ppc* and ppc*le as compatible for binfmt registrations
   * mention ACPI SLIC to RSDT id copying if slic table is supplied,
     thank you Tim Small for the patch (Closes: #765075)
   * apply 5 patches from upstream to fix a security issue in
     vmware-vga (Closes: #765496 CVE-2014-3689)
   * apply two patche from upstream to make qemu to work with samba4
     (Closes: #747636)
Checksums-Sha1:
 e68b0c1d77a89cd1dd110b3e0bdc5e38d2b6ac90 5152 qemu_2.1+dfsg-6.dsc
 6a57b4e2b513bc0e196edaefd695c9cb5f231961 81560 qemu_2.1+dfsg-6.debian.tar.xz
 ec1508bfaedb2ff2b223bfe5644fd088f5ddb55c 119682 qemu_2.1+dfsg-6_amd64.deb
 e7e6516893a33c878f6e760d8c6f5265246d8a25 48538 qemu-system_2.1+dfsg-6_amd64.deb
 9d2319f4af81c6f2cd4ea019fc08fc46515e7246 278666 qemu-system-common_2.1+dfsg-6_amd64.deb
 9817c13585bf9e1b24faa7ea964e6da9a0e75d35 5183470 qemu-system-misc_2.1+dfsg-6_amd64.deb
 6003fd59f5796d6312f22ad2ca621559fafd9c67 2227250 qemu-system-arm_2.1+dfsg-6_amd64.deb
 9231ba84f341eadffbb1fd9ff6ef1c94ca72cc35 2556076 qemu-system-mips_2.1+dfsg-6_amd64.deb
 9068a7e2e99a797466e93962fbb625e3c92b5c4b 2820706 qemu-system-ppc_2.1+dfsg-6_amd64.deb
 184f27345b19b0b6fe282692f4dc2bdddff4459a 1665768 qemu-system-sparc_2.1+dfsg-6_amd64.deb
 66e7727bb69350e0f4fbc042e366ab989c1e2c0c 2040342 qemu-system-x86_2.1+dfsg-6_amd64.deb
 7e144c145642857d1aec846f5e0e709ab80101ff 4907988 qemu-user_2.1+dfsg-6_amd64.deb
 bcbdb00088b407c2ee47aa3453f28a2985bdbdbf 6904450 qemu-user-static_2.1+dfsg-6_amd64.deb
 8d7c76d247c373b57af57ac4715ed75c859c1fcf 2652 qemu-user-binfmt_2.1+dfsg-6_amd64.deb
 7579cf2a382c9fcec20620e2c17240df7b4bd61e 478684 qemu-utils_2.1+dfsg-6_amd64.deb
 5e7d91eb315e0f8a6b97436d54dc5ee65637a2e4 133326 qemu-guest-agent_2.1+dfsg-6_amd64.deb
 c2d5a776d6d64cd14a2ae77c4c00819d0d3aac08 49558 qemu-kvm_2.1+dfsg-6_amd64.deb
Checksums-Sha256:
 ccb5ef340215528f33b9bdec54199ddabcf005e3573ff40c1b2e0467b899e187 5152 qemu_2.1+dfsg-6.dsc
 625c68c0f7c02dcd2decf93fad4694985a09d2ff49d55c0dac931432646d52ea 81560 qemu_2.1+dfsg-6.debian.tar.xz
 7340b3a3be5131d6478915ae46f9966c12879e5b0a5738e6ea5d44439d8577e4 119682 qemu_2.1+dfsg-6_amd64.deb
 d3ba0d00ac25a9ee6d964c103476b57ee44f52d5d4d609edc5f0273f608bb3e2 48538 qemu-system_2.1+dfsg-6_amd64.deb
 c26f30f3418da6102f604cf03f1f64ee56b187c4d9cc7d8e4277bf7206975bde 278666 qemu-system-common_2.1+dfsg-6_amd64.deb
 c75301916d9e8e2f62925026fdc97b394ff964c3c56b06166e496a9292cc2085 5183470 qemu-system-misc_2.1+dfsg-6_amd64.deb
 40f25b41ea7d688566d5f319269c2705f3cbc3d8cc56878d482264f3cbf6fdc6 2227250 qemu-system-arm_2.1+dfsg-6_amd64.deb
 acc65ad2ef7bac65f3a1689e9db1e831052a070294639b1a1c161beae5ef5777 2556076 qemu-system-mips_2.1+dfsg-6_amd64.deb
 014e8be956153ba784483f8b4fcc42ff2ff4d1406ba62075f808be56d78bb8b4 2820706 qemu-system-ppc_2.1+dfsg-6_amd64.deb
 6554cf7cc2b041056c22a078cc15fa3ce5be34b80200e0cb71eef44d2d88aac7 1665768 qemu-system-sparc_2.1+dfsg-6_amd64.deb
 a175462a2769e3ea2fa9da96b618e4846f505ed491cfa94f41be5321ebd42249 2040342 qemu-system-x86_2.1+dfsg-6_amd64.deb
 e2bd0cb5dd391ca3025bd54dc0e4d0cfe5479ee42207caf348d9f07cbe210cc1 4907988 qemu-user_2.1+dfsg-6_amd64.deb
 c17e6128281453e2af3970891c7e1aad7881aef1fb9bffdf1002321b99b378a7 6904450 qemu-user-static_2.1+dfsg-6_amd64.deb
 031459df5b9b09da64563fe31c62faa0ff5a3f5b829699390f37b2a105066245 2652 qemu-user-binfmt_2.1+dfsg-6_amd64.deb
 a6f29e930a82a9150bed34a6140896bacca787f73e156b221e3e21e22292dce1 478684 qemu-utils_2.1+dfsg-6_amd64.deb
 bac19bd49fb884d34b65ee104e8c43aac99d9b045157808878583e6c6a5c65f7 133326 qemu-guest-agent_2.1+dfsg-6_amd64.deb
 ba3b5c839c892886d7a716ad140d08b0ff498a43b4e9b3d87bcec0955010e6ab 49558 qemu-kvm_2.1+dfsg-6_amd64.deb
Files:
 c8d8ac62dfb374a0f602900d490556bb 5152 otherosfs optional qemu_2.1+dfsg-6.dsc
 e9cf94cf26abd215fcd1f67bcb68a0f5 81560 otherosfs optional qemu_2.1+dfsg-6.debian.tar.xz
 c3a7a87854f2a09ee644f00dd1e867ad 119682 otherosfs optional qemu_2.1+dfsg-6_amd64.deb
 e53f4dfb5ddfc40471595e21f716caa3 48538 otherosfs optional qemu-system_2.1+dfsg-6_amd64.deb
 8b35ba6ec6e5207c7ccc638b9f606fea 278666 otherosfs optional qemu-system-common_2.1+dfsg-6_amd64.deb
 d93f243000b9a5b1af78c14d462070e3 5183470 otherosfs optional qemu-system-misc_2.1+dfsg-6_amd64.deb
 71846a06fdc007f87aab21232438f289 2227250 otherosfs optional qemu-system-arm_2.1+dfsg-6_amd64.deb
 874888c99b376168803626769bafcf6c 2556076 otherosfs optional qemu-system-mips_2.1+dfsg-6_amd64.deb
 e06709d84f87c8483b3259167786acd9 2820706 otherosfs optional qemu-system-ppc_2.1+dfsg-6_amd64.deb
 56cb2c3ac4dabd995424c7350280bf7a 1665768 otherosfs optional qemu-system-sparc_2.1+dfsg-6_amd64.deb
 cc2b899895119f8ccb3ab0c824e15f4e 2040342 otherosfs optional qemu-system-x86_2.1+dfsg-6_amd64.deb
 5c0feeeb73bbd573e238843f73062e9d 4907988 otherosfs optional qemu-user_2.1+dfsg-6_amd64.deb
 8b73a5a59e873e47dd9018e04a5d0e60 6904450 otherosfs optional qemu-user-static_2.1+dfsg-6_amd64.deb
 01b44bb51855e3f6a64813c86754b2b7 2652 otherosfs optional qemu-user-binfmt_2.1+dfsg-6_amd64.deb
 cffeb540cd9e89828025d6d36898e265 478684 otherosfs optional qemu-utils_2.1+dfsg-6_amd64.deb
 470224d6a85a069347de6344240214f8 133326 otherosfs optional qemu-guest-agent_2.1+dfsg-6_amd64.deb
 c3e8ac98c88ed2a3d92e6d55c76a3221 49558 otherosfs optional qemu-kvm_2.1+dfsg-6_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEcBAEBAgAGBQJUV53oAAoJEL7lnXSkw9fbSEUH/i+zS1b291hembnaBuQCpd2n
0T+FzAZBG5Lihts1KFl3AuAwWj6XqGEe29yg69QP7dF1YMt8awkuP8lhCj/BOTlt
C5GcxfSTBKTp5mHxMKdVtFsMaavw8tw+EJlN+wP+/jcGhD4KocXQCOCTbrMhU3yN
p23CxvjC0sMqXnQf9pcviuZekZPJn+6PvN4LQMvWkrQ+34s+Lvwq7Ufh8uPXi+Ry
OSsMTb7cZMPRMGVVVGhuXAzytk550mBf3C4n1XpM8iJ46FDmJuQZO2L5W43yLINt
u9JV1+YxBQ8nEqdU0yd91ZgxpiVN8OQx97sF7nLP14FgiD2ekBm/kJHfyRF/P0k=
=L1tY
-----END PGP SIGNATURE-----




Reply sent to Michael Tokarev <mjt@tls.msk.ru>:
You have taken responsibility. (Fri, 07 Nov 2014 15:36:14 GMT) (full text, mbox, link).


Notification sent to Michael Tokarev <mjt@tls.msk.ru>:
Bug acknowledged by developer. (Fri, 07 Nov 2014 15:36:14 GMT) (full text, mbox, link).


Message #17 received at 765496-close@bugs.debian.org (full text, mbox, reply):

From: Michael Tokarev <mjt@tls.msk.ru>
To: 765496-close@bugs.debian.org
Subject: Bug#765496: fixed in qemu-kvm 1.1.2+dfsg-6+deb7u5
Date: Fri, 07 Nov 2014 15:32:06 +0000
Source: qemu-kvm
Source-Version: 1.1.2+dfsg-6+deb7u5

We believe that the bug you reported is fixed in the latest version of
qemu-kvm, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 765496@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Tokarev <mjt@tls.msk.ru> (supplier of updated qemu-kvm package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 05 Nov 2014 10:45:16 +0300
Source: qemu-kvm
Binary: qemu-kvm qemu-kvm-dbg kvm
Architecture: source amd64
Version: 1.1.2+dfsg-6+deb7u5
Distribution: wheezy-security
Urgency: medium
Maintainer: Michael Tokarev <mjt@tls.msk.ru>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Description: 
 kvm        - dummy transitional package from kvm to qemu-kvm
 qemu-kvm   - Full virtualization on x86 hardware
 qemu-kvm-dbg - Debugging info for qemu-kvm
Closes: 765496
Changes: 
 qemu-kvm (1.1.2+dfsg-6+deb7u5) wheezy-security; urgency=medium
 .
   * apply 5 patches backported from upstream to fix a security issue in
     vmware-vga (Closes: #765496 CVE-2014-3689)
   * vnc-sanitize-bits_per_pixel-from-the-client-CVE-2014-7815.patch
     from upstream (Closes: CVE-2014-7815)
Checksums-Sha1: 
 e212e94665c00fa45e648e233c8f1e9cc335b031 2151 qemu-kvm_1.1.2+dfsg-6+deb7u5.dsc
 6644c44ba8932c426f32f995c8fd90e0574c2779 91758 qemu-kvm_1.1.2+dfsg-6+deb7u5.debian.tar.gz
 8308e2817b5e13c0bc438a23e9b6320a29bf51e8 1678988 qemu-kvm_1.1.2+dfsg-6+deb7u5_amd64.deb
 2de452190822dd553b0eac401b9750cba1fde4c0 5272210 qemu-kvm-dbg_1.1.2+dfsg-6+deb7u5_amd64.deb
 797a98dd36ecf65cd642db10b21b4a6754ac54f1 23998 kvm_1.1.2+dfsg-6+deb7u5_amd64.deb
Checksums-Sha256: 
 d5d441f0e60a850a27361a251e096f2251ea86109c218cd0d6ccae440338d8a7 2151 qemu-kvm_1.1.2+dfsg-6+deb7u5.dsc
 ab64722ce1222c195402f1ec117ab53208eb8b04960e83fa7707b68a149972c3 91758 qemu-kvm_1.1.2+dfsg-6+deb7u5.debian.tar.gz
 ff61a6eb89bbf466b7b8a5bf1956d149a19800e8fd50b90d3a038b697da83e8b 1678988 qemu-kvm_1.1.2+dfsg-6+deb7u5_amd64.deb
 b712570f91b0cac1251303ee49ea26012db99d3c3d1cacc51f504668d629707b 5272210 qemu-kvm-dbg_1.1.2+dfsg-6+deb7u5_amd64.deb
 47a8a281490005533374c7e9cd01c8a0a029a22df63dc70c29560dc9b6e11cb7 23998 kvm_1.1.2+dfsg-6+deb7u5_amd64.deb
Files: 
 2c81bb4c42c109166df5642723f8ba01 2151 misc optional qemu-kvm_1.1.2+dfsg-6+deb7u5.dsc
 767e05e0293bf3366cb285f4ec85a0b0 91758 misc optional qemu-kvm_1.1.2+dfsg-6+deb7u5.debian.tar.gz
 e5bde3bfd823fc25ee0d9bdde60e5c12 1678988 misc optional qemu-kvm_1.1.2+dfsg-6+deb7u5_amd64.deb
 2914917ce7a18f3ae031454f7493eb2f 5272210 debug extra qemu-kvm-dbg_1.1.2+dfsg-6+deb7u5_amd64.deb
 78d5a8c605be517c7a659295001408b2 23998 oldlibs extra kvm_1.1.2+dfsg-6+deb7u5_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEcBAEBAgAGBQJUWy6SAAoJEL7lnXSkw9fb7m4H/1Wj0AHbP8W/gQpwsXkVsnDP
4PA1QR6rLw3eYB0ihfQyFGzHB0LSnrgXQZV9Mxm8SE1r53wxotfD/m7mOORkT+sD
eGt3WVb6DcteN9864Efdfv2ElbSgo5ix9uDXwHlRAdj1gPX4ALqqnMXdIJiXpa8y
QfWRVgxSoZeYm7OXGFfKqn3noC910+89ZwpuBNSaqTnuISJXFe6i4VGqrsTJj2/S
ybpzLfDcAkPxnh61rD1/sXkIkT6XKIqMshbITAzpUf7sxmRFAD2h7UCpNI+BQ+z7
33Zk+vDuXBgGbcOmZ/+u6ML0BR2+AX9M4IQJQV1Qjt0hglmW2sJj9c6RifLVPLk=
=Q+km
-----END PGP SIGNATURE-----




Reply sent to Michael Tokarev <mjt@tls.msk.ru>:
You have taken responsibility. (Fri, 07 Nov 2014 23:21:10 GMT) (full text, mbox, link).


Notification sent to Michael Tokarev <mjt@tls.msk.ru>:
Bug acknowledged by developer. (Fri, 07 Nov 2014 23:21:10 GMT) (full text, mbox, link).


Message #22 received at 765496-close@bugs.debian.org (full text, mbox, reply):

From: Michael Tokarev <mjt@tls.msk.ru>
To: 765496-close@bugs.debian.org
Subject: Bug#765496: fixed in qemu 1.1.2+dfsg-6a+deb7u5
Date: Fri, 07 Nov 2014 23:17:14 +0000
Source: qemu
Source-Version: 1.1.2+dfsg-6a+deb7u5

We believe that the bug you reported is fixed in the latest version of
qemu, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 765496@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Tokarev <mjt@tls.msk.ru> (supplier of updated qemu package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Wed, 05 Nov 2014 10:45:16 +0300
Source: qemu
Binary: qemu qemu-keymaps qemu-system qemu-user qemu-user-static qemu-utils
Architecture: source all amd64
Version: 1.1.2+dfsg-6a+deb7u5
Distribution: wheezy-security
Urgency: medium
Maintainer: Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Description: 
 qemu       - fast processor emulator
 qemu-keymaps - QEMU keyboard maps
 qemu-system - QEMU full system emulation binaries
 qemu-user  - QEMU user mode emulation binaries
 qemu-user-static - QEMU user mode emulation binaries (static version)
 qemu-utils - QEMU utilities
Closes: 765496
Changes: 
 qemu (1.1.2+dfsg-6a+deb7u5) wheezy-security; urgency=medium
 .
   * apply 5 patches backported from upstream to fix a security issue in
     vmware-vga (Closes: #765496 CVE-2014-3689)
   * vnc-sanitize-bits_per_pixel-from-the-client-CVE-2014-7815.patch
     from upstream (Closes: CVE-2014-7815)
Checksums-Sha1: 
 97b70b2cfabda1d5b1f1c5c5b23df480cbbd8a9f 2634 qemu_1.1.2+dfsg-6a+deb7u5.dsc
 e8280b293f798d356567737444c0e120d71c51a1 103543 qemu_1.1.2+dfsg-6a+deb7u5.debian.tar.gz
 aabe0497dcee055755ece4ab57ff845410ca7160 49574 qemu-keymaps_1.1.2+dfsg-6a+deb7u5_all.deb
 3fc4ac1d1c27dabf926797f60944d4f4b7cdb9ce 114772 qemu_1.1.2+dfsg-6a+deb7u5_amd64.deb
 343a3103fb47cf52ceada893da672535dca0c62c 27896058 qemu-system_1.1.2+dfsg-6a+deb7u5_amd64.deb
 731d143bd95b6b575678f34d8766bcc2922fafe8 7721522 qemu-user_1.1.2+dfsg-6a+deb7u5_amd64.deb
 2a13445e1f8cae19f2dd8943d99fc24db5916da4 16568362 qemu-user-static_1.1.2+dfsg-6a+deb7u5_amd64.deb
 1598e1786a3a20497473f4d22c4b7c034bffd70d 663864 qemu-utils_1.1.2+dfsg-6a+deb7u5_amd64.deb
Checksums-Sha256: 
 f0e29ae502dcf72d386c7c2198adb893820999b77dce90d5816b149d09073038 2634 qemu_1.1.2+dfsg-6a+deb7u5.dsc
 b0f718b20eaa6277810e506891588a7bdeeba4356b1585c71f17131b48bf35b8 103543 qemu_1.1.2+dfsg-6a+deb7u5.debian.tar.gz
 ee2fe0585bcf1e428e501935d952ef0b10d1ec7c073cf75c6477b18b53b547cb 49574 qemu-keymaps_1.1.2+dfsg-6a+deb7u5_all.deb
 89bb3e98b0d4ecdb7b99fbf0c43b9b9b8a6219944d642771df96bd8c8c48860a 114772 qemu_1.1.2+dfsg-6a+deb7u5_amd64.deb
 146144147a74866c59809c937fe29e5d8ec560516f29cc0fe9a253a1a9745a0e 27896058 qemu-system_1.1.2+dfsg-6a+deb7u5_amd64.deb
 95cda0aed6f86151b0b61353e90029540dee1e62350173173e718203a0591757 7721522 qemu-user_1.1.2+dfsg-6a+deb7u5_amd64.deb
 1fc3f5a68c79170fe57f0f54c21249822ae6ea88d54b64b93b2b6e9ec31035c4 16568362 qemu-user-static_1.1.2+dfsg-6a+deb7u5_amd64.deb
 eb8f9b13ace5b38f806d90e035b1ee1caf0e01ac064dafe7001d9dc176f83113 663864 qemu-utils_1.1.2+dfsg-6a+deb7u5_amd64.deb
Files: 
 fc01f87ed3beeacdb23b3a8fc7d85d5d 2634 misc optional qemu_1.1.2+dfsg-6a+deb7u5.dsc
 875eb959d82afb232768bb7b84a8feaf 103543 misc optional qemu_1.1.2+dfsg-6a+deb7u5.debian.tar.gz
 32e32fdf9f7485284fce6ce78f38c5fd 49574 misc optional qemu-keymaps_1.1.2+dfsg-6a+deb7u5_all.deb
 ea9fdddbb5193d13d92939a44e063e4b 114772 misc optional qemu_1.1.2+dfsg-6a+deb7u5_amd64.deb
 2eafc6e16ece43f168c095123a76c7a1 27896058 misc optional qemu-system_1.1.2+dfsg-6a+deb7u5_amd64.deb
 21ade2010eab0ee749cd7860278c5621 7721522 misc optional qemu-user_1.1.2+dfsg-6a+deb7u5_amd64.deb
 a1ba751139b35b98f67316f4f73d9492 16568362 misc optional qemu-user-static_1.1.2+dfsg-6a+deb7u5_amd64.deb
 8bcec4c019bb36836646548d75b21947 663864 misc optional qemu-utils_1.1.2+dfsg-6a+deb7u5_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEcBAEBAgAGBQJUWy6TAAoJEL7lnXSkw9fb9sIH/iF8Zi2nljh5wJHAtX5CJx8L
wHpSgTTkeg0S5LuqrX4Y7qtmGkn3j0EEWs70rq4xRysRnFaAEjfO5kYJquFM5PBH
sAwr0sV8jO4nVi8KZlA47bJbwz86mQxLkL7lesuhDPmUzp1Iu4GYXVPp+7p7RnOX
PjsB7ZFLPQenAg4iirGQP/2zDQqJeimwHLwMyHof64VPoCHD7KdrNAkI+X38zSRi
+QmlD00ZllA5hDqJv9Xuhv9uH4pdkd9Ou7lzLfzP6x9mOM83cxw7FfDxI7bshFJJ
KdHZ5Hj04SM4eEspCA98joxszgUrCGyBgFa6G338H6IFeWyZ6TihGX3Ex9L+Wvo=
=43oW
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 07 Dec 2014 07:34:17 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 13:19:00 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.