qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: "Daniel P. Berrange" <berrange@redhat.com>
To: Michael Roth <mdroth@linux.vnet.ibm.com>
Cc: aliguori@us.ibm.com, pmatouse@redhat.com, qemu-devel@nongnu.org,
	qemu-stable@nongnu.org, lersek@redhat.com, lveyde@redhat.com
Subject: Re: [Qemu-devel] [ANNOUNCE] QEMU 1.5.2 Stable released
Date: Fri, 26 Jul 2013 11:09:39 +0100	[thread overview]
Message-ID: <20130726100939.GD18015@redhat.com> (raw)
In-Reply-To: <20130725214443.16294.56339@loki>

On Thu, Jul 25, 2013 at 04:44:43PM -0500, Michael Roth wrote:
> The QEMU v1.5.2 stable release is now available at:
> 
>   http://wiki.qemu.org/download/qemu-1.5.2.tar.bz2
> 
> This is release is solely to address a security issue (CVE-2013-2231) found
> in the QEMU Guest Agent on Windows. More details on the nature of the CVE
> can be found here:

It is fairly common to include the CVE number in the commit message subject
line as in this case, but sometimes people only put them in the body, or even
forgot completely. Other times you might not even realize the bug fixed was a
CVE until well after the commit is pushed to master.

So for libvirt we just started a policy of creating named tags for every
CVE fix [1], so you can just do  'git show CVE-2013-2231' and identify
the patch which fixed the issue. I mention this in case QEMU maintainers
think it might be a useful policy/approach for QEMU's GIT too.

Regards,
Daniel

[1] And retroactively tagged all previous fixes.
-- 
|: http://berrange.com      -o-    http://www.flickr.com/photos/dberrange/ :|
|: http://libvirt.org              -o-             http://virt-manager.org :|
|: http://autobuild.org       -o-         http://search.cpan.org/~danberr/ :|
|: http://entangle-photo.org       -o-       http://live.gnome.org/gtk-vnc :|

  parent reply	other threads:[~2013-07-26 10:09 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-07-25 21:44 [Qemu-devel] [ANNOUNCE] QEMU 1.5.2 Stable released Michael Roth
2013-07-25 22:04 ` Laszlo Ersek
2013-07-26 10:09 ` Daniel P. Berrange [this message]
2013-07-31 14:19 ` Miroslav Rezanina
2013-08-03  0:00   ` Michael Roth

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20130726100939.GD18015@redhat.com \
    --to=berrange@redhat.com \
    --cc=aliguori@us.ibm.com \
    --cc=lersek@redhat.com \
    --cc=lveyde@redhat.com \
    --cc=mdroth@linux.vnet.ibm.com \
    --cc=pmatouse@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=qemu-stable@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).