From mboxrd@z Thu Jan 1 00:00:00 1970 From: Keir Fraser Subject: Re: [PATCH] Fix CVE-2007-1320, CVE-2007-1321 , CVE-2007-1322, CVE-2007-1323 and CVE-2007-1366 Date: Tue, 01 May 2007 14:44:38 +0100 Message-ID: References: <200705011629.20671.caglar@pardus.org.tr> Mime-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <200705011629.20671.caglar@pardus.org.tr> List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Sender: xen-devel-bounces@lists.xensource.com Errors-To: xen-devel-bounces@lists.xensource.com To: caglar@pardus.org.tr, xen-devel@lists.xensource.com List-Id: xen-devel@lists.xenproject.org On 1/5/07 14:29, "S.=C3=87a=C4=9Flar Onur" wrote: > If anybody interested, attached patch (against 3.0.4) fixes CVE-2007-1320= , > CVE-2007-1321 , CVE-2007-1322, CVE-2007-1323 and CVE-2007-1366 which affe= cts > qemu and also seems valid for xen. Is the patch from upstream qemu? We have our own patches to fix these issue= s in 3.0.5-rc, but we'd consider an alternative that keeps us closer to upstream qemu (albeit a later qemu than we build against). -- Keir