Summary
The remote host is missing an update to qemu
announced via advisory DSA 1799-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201799-1
Insight
Several vulnerabilities have been discovered in the QEMU processor emulator. The Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2008-0928
Ian Jackson discovered that range checks of file operations on emulated disk devices were insufficiently enforced.
CVE-2008-1945
It was discovered that an error in the format auto detection of removable media could lead to the disclosure of files in the host system.
CVE-2008-4539
A buffer overflow has been found in the emulation of the Cirrus graphics adaptor.
For the old stable distribution (etch), these problems have been fixed in version 0.8.2-4etch3.
For the stable distribution (lenny), these problems have been fixed in version 0.9.1-10lenny1.
For the unstable distribution (sid), these problems have been fixed in version 0.9.1+svn20081101-1.
We recommend that you upgrade your qemu packages.
Severity
Classification
-
CVE CVE-2008-0928, CVE-2008-1945, CVE-2008-4539 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities