OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[SA25095] Debian update for qemu

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Tue May 01 2007 - 07:47:05 CDT


----------------------------------------------------------------------

Try a new way to discover vulnerabilities that ALREADY EXIST in your
IT infrastructure.

Join the FREE BETA test of the Network Software Inspector (NSI)!
http://secunia.com/network_software_inspector/

The NSI enables you to INSPECT, DISCOVER, and DOCUMENT
vulnerabilities in more than 4,000 different Windows applications.

----------------------------------------------------------------------

TITLE:
Debian update for qemu

SECUNIA ADVISORY ID:
SA25095

VERIFY ADVISORY:
http://secunia.com/advisories/25095/

CRITICAL:
Moderately critical

IMPACT:
Security Bypass, DoS

WHERE:
From remote

OPERATING SYSTEM:
Debian GNU/Linux 3.1
http://secunia.com/product/5307/
Debian GNU/Linux unstable alias sid
http://secunia.com/product/530/
Debian GNU/Linux 4.0
http://secunia.com/product/13844/

DESCRIPTION:
Debian has issued an update for qemu. This fixes some
vulnerabilities, which can be exploited by malicious users to bypass
certain security restrictions and cause a DoS (Denial of Service).

For more information:
SA25073

SOLUTION:
Apply updated packages.

-- Debian GNU/Linux 3.1 alias sarge --

Source archives:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.6.1+20050407-1sarge1.dsc
Size/MD5 checksum: 860 0d4d669e862d4249af1fd6d4e62ed21e
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.6.1+20050407-1sarge1.diff.gz
Size/MD5 checksum: 456776 9940e2b1c7e3edce24a941d79cc45f1c
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.6.1+20050407.orig.tar.gz
Size/MD5 checksum: 991912 a4cb70b9b701668c1c37705f9b5baae6

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.6.1+20050407-1sarge1_i386.deb
Size/MD5 checksum: 1888278 b3fd3a2a4c01ccd3a22ffb079c2da48a

PowerPC architecture:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.6.1+20050407-1sarge1_powerpc.deb
Size/MD5 checksum: 1819756 d95ad449adf33a288cb509a5cf580593

-- Debian GNU/Linux 4.0 alias etch --

Source archives:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch1.dsc
Size/MD5 checksum: 1122 9d55f0fd6f5261bff1a83f6ea0652afb
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch1.diff.gz
Size/MD5 checksum: 63407 e4f93234058f38d4fffbacb9524bbaa4
http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2.orig.tar.gz
Size/MD5 checksum: 1501979 312eebc1386cca2e9b30a40763ab9c0d

AMD64 architecture:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch1_amd64.deb
Size/MD5 checksum: 3700158 ced2cb8925aadb4abb1d0bf9f49aaace

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch1_i386.deb
Size/MD5 checksum: 3675760 20e6e9eb0ea92b043397e3ea348a3925

PowerPC architecture:

http://security.debian.org/pool/updates/main/q/qemu/qemu_0.8.2-4etch1_powerpc.deb
Size/MD5 checksum: 3578440 e604fc75cead026b2581800f35c1f5b4

-- Debian GNU/Linux unstable alias sid --

Reportedly, the vulnerabilities will be fixed soon.

ORIGINAL ADVISORY:
http://lists.debian.org/debian-security-announce/debian-security-announce-2007/msg00040.html

OTHER REFERENCES:
SA25073:
http://secunia.com/advisories/25073/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------