-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3067-1 security@debian.org http://www.debian.org/security/ Salvatore Bonaccorso November 06, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : qemu-kvm CVE ID : CVE-2014-3689 CVE-2014-7815 Several vulnerabilities were discovered in qemu-kvm, a full virtualization solution on x86 hardware. CVE-2014-3689 The Advanced Threat Research team at Intel Security reported that guest provided parameter were insufficiently validated in rectangle functions in the vmware-vga driver. A privileged guest user could use this flaw to write into qemu address space on the host, potentially escalating their privileges to those of the qemu host process. CVE-2014-7815 James Spadaro of Cisco reported insufficiently sanitized bits_per_pixel from the client in the QEMU VNC display driver. An attacker having access to the guest's VNC console could use this flaw to crash the guest. For the stable distribution (wheezy), these problems have been fixed in version 1.1.2+dfsg-6+deb7u5. We recommend that you upgrade your qemu-kvm packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJUW5mZAAoJEAVMuPMTQ89E7s0P/3GjkoZuKDCASw/iiS1K6Xho q5kGk2AYa0Va0JABdp8KLSguwkVbRb9LG080akyQCLJfcCGg30qOUMc4JsHEGjHs Vk8XDh1mQ4KmWHpjdN8WA71jqgejPcx5Ruxn/DLOhA8IbPQNBAzULHgq5G0wu5nn L6FHT9tnfckm4MAtWGqjmulzjXUp0WpTn5q0Hdfh1niXPr2yG3o+GdFgGZKpW9D+ 6Blspv7vwGzertHq+QndV8tMrel5WzZ2dgafOxrSckzWUPoE/GQiRu71tlZwVZuH 0FvU9MGRX8KyExhhJUBbhdet3Ki88cuJiDbncER8XGItnz5U9uyZb88QXT7cHJ/J naJ6t1r7y10nhhVAevyBFcjRfCXxSvC7ID6XWP+MY3MiAIEebQyCk4OVlK0CIiJG ff9dX4I67G5SNKeMMCQEiBNmBua4HO1LNUQ86plTB5tj5gFfenldVhIG2iJjhi3/ p7EzyWQnEa+qDREXR884P9kf6hl2JNOGhlofIJI5A+xC59PQfozeKlMTdldrr2v4 UvWR+oiTPNlrE1xC8cWBHFzo9pvy2pTFbcKG4dZH+kkq80c9R664MWHZj7tFMp5M DpkHLXmZT2/c51AYlKsAOB26QmBwnI/l/k4+c/miQ2a4ETJnrdYfxXLNr4Il0Arh vPiNq8zMmq03KtFxA0DE =tlpB -----END PGP SIGNATURE-----