All of lore.kernel.org
 help / color / mirror / Atom feed
* QEMU "drive_init()" Disk Format Security Bypass
@ 2008-05-08 15:00 Eren Türkay
  2008-05-08 16:58 ` Ian Jackson
  0 siblings, 1 reply; 26+ messages in thread
From: Eren Türkay @ 2008-05-08 15:00 UTC (permalink / raw)
  To: xen-devel

Hello,

Today, a security flaw in Qemu was released at secunia [0] which was fixed in 
qemu svn repository.

Xen uses part of a qemu code including "vl.c" in which the security flaw 
appeared. I suspect that Xen is effected by this vulnerability too but I 
couldn't find same lines in vl.c and I'm not sure about it.

Could someone look at this issue and shed a light? If Xen is effected, I would 
really appreciate a patch.

[0] http://secunia.com/advisories/30111/

My best regards,
Eren

^ permalink raw reply	[flat|nested] 26+ messages in thread
* QEMU "drive_init()" Disk Format Security Bypass
@ 2008-05-08 14:02 Eren Türkay
  2008-05-08 14:12 ` Daniel P. Berrange
  0 siblings, 1 reply; 26+ messages in thread
From: Eren Türkay @ 2008-05-08 14:02 UTC (permalink / raw)
  To: kvm-devel

Hello,

An advisory about $subject was released today by secunia. The security flaw 
was fixed in QEmu SVN repository.

Kvm uses some of the old version of qemu that I can't backport patch I grabbed 
from qemu svn repository. Could you look at this issue and provide a patch?

http://secunia.com/advisories/30111/

Svn commit: 
http://svn.savannah.gnu.org/viewvc/?view=rev&root=qemu&revision=4277

Discussion: http://lists.gnu.org/archive/html/qemu-devel/2008-04/msg00675.html

Regards,
Eren

-------------------------------------------------------------------------
This SF.net email is sponsored by the 2008 JavaOne(SM) Conference 
Don't miss this year's exciting event. There's still time to save $100. 
Use priority code J8TL2D2. 
http://ad.doubleclick.net/clk;198757673;13503038;p?http://java.sun.com/javaone

^ permalink raw reply	[flat|nested] 26+ messages in thread

end of thread, other threads:[~2008-06-18 11:36 UTC | newest]

Thread overview: 26+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-05-08 15:00 QEMU "drive_init()" Disk Format Security Bypass Eren Türkay
2008-05-08 16:58 ` Ian Jackson
2008-05-08 17:12   ` Eren Türkay
2008-05-08 17:12   ` Daniel P. Berrange
2008-05-08 17:18     ` Keir Fraser
2008-05-08 17:19     ` Ian Jackson
2008-05-08 17:23       ` Daniel P. Berrange
2008-05-08 17:27         ` Ian Jackson
2008-05-08 17:30           ` Daniel P. Berrange
2008-05-09 15:54             ` [PATCH] " Ian Jackson
2008-05-13 17:16               ` Ian Jackson
2008-05-30  9:00                 ` Markus Armbruster
2008-05-30 13:37                   ` Ian Jackson
2008-06-13 15:13                     ` Ian Jackson
2008-06-16 15:38                       ` Markus Armbruster
2008-06-16 15:45                         ` Ian Jackson
2008-06-16 16:37                           ` Markus Armbruster
2008-06-16 16:55                             ` Ian Jackson
2008-06-17 16:58                               ` Markus Armbruster
2008-06-17 16:59                               ` [PATCH] ioemu: Disable format auto-probing in monitor command change Markus Armbruster
2008-06-18 10:22                                 ` Ian Jackson
2008-06-18 11:36                                   ` Markus Armbruster
2008-06-13 15:17                   ` [PATCH] QEMU "drive_init()" Disk Format Security Bypass Ian Jackson
  -- strict thread matches above, loose matches on Subject: below --
2008-05-08 14:02 Eren Türkay
2008-05-08 14:12 ` Daniel P. Berrange
2008-05-08 14:17   ` Eren Türkay

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.