Debian update for qemu
Secunia Advisory: SA25095
Release Date: 2007-05-01
Last Update: 2007-05-08
Popularity: 4,847 views

Critical:
Moderately critical
Impact: Security Bypass
DoS
Where: From remote
Solution Status: Vendor Patch

OS:Debian GNU/Linux 3.1
Debian GNU/Linux 4.0
Debian GNU/Linux unstable alias sid

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2007-1320
CVE-2007-1321
CVE-2007-1322
CVE-2007-1323
CVE-2007-1366


Description:
Debian has issued an update for qemu. This fixes some vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions and cause a DoS (Denial of Service).

For more information:
SA25073

Solution:
Apply updated packages.

-- Debian GNU/Linux 3.1 alias sarge --

Source archives:

http://security.debian.org/pool/updat.../qemu/qemu_0.6.1+20050407-1sarge1.dsc
Size/MD5 checksum: 860 0d4d669e862d4249af1fd6d4e62ed21e
http://security.debian.org/pool/updat...u/qemu_0.6.1+20050407-1sarge1.diff.gz
Size/MD5 checksum: 456776 9940e2b1c7e3edce24a941d79cc45f1c
http://security.debian.org/pool/updat.../qemu/qemu_0.6.1+20050407.orig.tar.gz
Size/MD5 checksum: 991912 a4cb70b9b701668c1c37705f9b5baae6

Intel IA-32 architecture:

http://security.debian.org/pool/updat.../qemu_0.6.1+20050407-1sarge1_i386.deb
Size/MD5 checksum: 1888278 b3fd3a2a4c01ccd3a22ffb079c2da48a

PowerPC architecture:

http://security.debian.org/pool/updat...mu_0.6.1+20050407-1sarge1_powerpc.deb
Size/MD5 checksum: 1819756 d95ad449adf33a288cb509a5cf580593


-- Debian GNU/Linux 4.0 alias etch --

Source archives:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch1.dsc
Size/MD5 checksum: 1122 9d55f0fd6f5261bff1a83f6ea0652afb
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch1.diff.gz
Size/MD5 checksum: 63407 e4f93234058f38d4fffbacb9524bbaa4
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2.orig.tar.gz
Size/MD5 checksum: 1501979 312eebc1386cca2e9b30a40763ab9c0d

AMD64 architecture:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch1_amd64.deb
Size/MD5 checksum: 3700158 ced2cb8925aadb4abb1d0bf9f49aaace

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch1_i386.deb
Size/MD5 checksum: 3675760 20e6e9eb0ea92b043397e3ea348a3925

PowerPC architecture:

http://security.debian.org/pool/updat.../q/qemu/qemu_0.8.2-4etch1_powerpc.deb
Size/MD5 checksum: 3578440 e604fc75cead026b2581800f35c1f5b4

-- Debian GNU/Linux unstable alias sid --

Reportedly, the vulnerabilities will be fixed soon.

Original Advisory:
http://lists.debian.org/debian-securi...-security-announce-2007/msg00040.html

Other References:
SA25073:
http://secunia.com/advisories/25073/


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Today
New advisories: 5
New vulnerabilities: 6
Updated advisories: 9

Moderately // 23 views
Gentoo update for courier-authlib

5th Sep, 2008
New advisories: 14
New vulnerabilities: 18
Updated advisories: 22

Less // 315 views
Fedora update for xastir
Less // 334 views
Fedora update for samba
Less // 330 views
Fedora update for bitlbee

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Linux Kernel "listxattr" Memory Corruption and CHRP Denial of Service // 50 views
2. Trend Micro Products Web Management Authentication Bypass // 40 views
3. Simple Machines Forum Password Reset Vulnerability // 35 views
4. VLC Media Player Multiple Vulnerabilities // 32 views
5. Opera Multiple Vulnerabilities // 32 views
6. Adobe Flash Player Multiple Vulnerabilities // 28 views
7. Microsoft Word Malformed Object Pointer Vulnerability // 26 views
8. phpAdultSite CMS SQL Injection And Cross-Site Scripting // 24 views
9. Microsoft Office Two Code Execution Vulnerabilities // 23 views
10. 3Com Wireless 8760 Access Point HTTP Request Processing Denial of Service // 23 views