-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4506-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 24, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : qemu CVE ID : CVE-2018-20815 CVE-2019-13164 CVE-2019-14378 Debian Bug : 873012 933741 931351 Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, the execution of arbitrary code or bypass of ACLs. In addition this update fixes a regression which could cause NBD connections to hang. For the oldstable distribution (stretch), these problems have been fixed in version 1:2.8+dfsg-6+deb9u8. We recommend that you upgrade your qemu packages. For the detailed security status of qemu please refer to its security tracker page at: https://security-tracker.debian.org/tracker/qemu Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl1hCR8ACgkQEMKTtsN8 TjbIsQ//RgsOLWDU5rkXicnpyEhAG5QwkZijXFkIbrhvDuQdYThZzJKT0AdFFAti ZzdfLxnc4arR160CoccIcw0J4pESoRcE/LWid7hNhCSpc9WX4KZc5cabwef0VuLw 4TAlqWMzPrV/1Hj5r2YGxb0OWO6YkWgcjJx0homD2b6ctW/BHh5Y+JyEF2BmbXIi 667vzxPT/c+jYg2dYYmhtpVkbEX2GLmg2tPssWrGeIRiYR5vwFHevQJeHS7rzyZ2 7CCpbx7ktv7jUea44iUYfsImmejEjcAeUSYj7fnEbmYeyywmDbVY6uEtSFKv5INn K74ZCwC1mQOmb8DZBnG1noDh62u8eBoe/CIl4aH1KBbd0+Y3hmdfIFbE+e3f2LVt ORuIrQJDm19ZmAx+C78ifWJL77KFS0Gvqsp3Qipak7XGyaEwTwUavriYwW9VyJVL tP5yKXHstJWDV8oyQZ3w+GPLJH4p1G0cquy3Dn/Ne5dE9d3Q/w5Q5v5UNYCuqtDL RwzaM7BUQXw2tO0cG2Q7O4e6iTq5XbEzR35cngIy6wDs67WnuH0Wvwfwt8vWNWpW cIKg5UH9J2CXYmlzfKOkE9IoiKlAAhWClDPeFvaBJyZMFDqFMzZysht+/1ywbT7k IX2oSA9Q+tu1sXTHHtMI9oUDs7MjfUpcQO+L5Ua/SbTm2uKA6sg= =Vlo1 -----END PGP SIGNATURE-----