Summary
The remote host is missing an update to xen-qemu-dm-4.0 announced via advisory DSA 2404-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202404-1
Insight
Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of QEMU, which is used in the xen-qemu-dm-4.0 packages. This vulnerability might enable to malicious guest systems to crash the host system or escalate their privileges.
The old stable distribution (lenny) does not contain the xen-qemu-dm-4.0 package.
For the stable distribution (squeeze), this problem has been fixed in version 4.0.1-2+squeeze1.
The testing distribution (wheezy) and the unstable distribution (sid) will be fixed soon.
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/
Severity
Classification
-
CVE CVE-2012-0029 -
CVSS Base Score: 7.4
AV:A/AC:M/Au:S/C:C/I:C/A:C
Related Vulnerabilities