From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:45364) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1V2SI3-0003YC-0T for qemu-devel@nongnu.org; Thu, 25 Jul 2013 16:37:36 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1V2SI1-0004qN-Pr for qemu-devel@nongnu.org; Thu, 25 Jul 2013 16:37:34 -0400 Sender: fluxion From: Michael Roth Date: Thu, 25 Jul 2013 15:37:21 -0500 Message-Id: <1374784644-29078-1-git-send-email-mdroth@linux.vnet.ibm.com> Subject: [Qemu-devel] [PULL 0/3] qemu-ga: security fixes for CVE-2013-2231 List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: pmatouse@redhat.com, aliguori@us.ibm.com, lersek@redhat.com, qemu-stable@nongnu.org, lveyde@redhat.com More details on the nature of the CVE are available here: http://seclists.org/oss-sec/2013/q3/161 The following changes since commit d2f5ea9704af781d4cf14e4be08bb4e37a180260: pc-testdev: add I/O port to test memory.c auto split/combine (2013-07-25 08:12:28 -0500) are available in the git repository at: git://github.com/mdroth/qemu.git qga-pull-2013-7-25 for you to fetch changes up to 340d51df5592c5c11fc3885f7bdedbe581b87366: qga: escape cmdline args when registering win32 service (CVE-2013-2231) (2013-07-25 14:49:04 -0500) ---------------------------------------------------------------- Laszlo Ersek (3): qga/service-win32.c: diagnostic output should go to stderr ga_install_service(): nest error paths more idiomatically qga: escape cmdline args when registering win32 service (CVE-2013-2231) qga/service-win32.c | 105 ++++++++++++++++++++++++++++++++++++++++++--------- 1 file changed, 88 insertions(+), 17 deletions(-)