Package: qemu-system-x86 Version: 2.0.0+dfsg-6+b1 Severity: important The local 9p support supports two security modules that map the information to either extended attributes or files.
The mappes xattr support dumps all information as raw bytes in the host endianes, without any normalization. This makes the information not portable and may lead to privilege escalation in the guest. Bastian -- System Information: Debian Release: jessie/sid APT prefers testing APT policy: (990, 'testing'), (500, 'unstable'), (500, 'stable'), (1, 'experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 3.14-1-amd64 (SMP w/4 CPU cores) Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Versions of packages qemu-system-x86 depends on: ii ipxe-qemu 1.0.0+git-20131111.c3d1e78-2 ii libaio1 0.3.109-4 ii libasound2 1.0.28-1 ii libbluetooth3 4.101-4.1 ii libbrlapi0.6 5.0-2+b1 ii libc6 2.19-7 ii libcurl3-gnutls 7.37.0-1+b1 ii libfdt1 1.4.0+dfsg-1 ii libgcc1 1:4.9.0-7 ii libglib2.0-0 2.40.0-3 ii libgnutls-deb0-28 3.2.15-3 ii libiscsi2 1.11.0-4 ii libjpeg8 8d1-1 ii libncurses5 5.9+20140118-1 ii libpixman-1-0 0.32.6-1 ii libpng12-0 1.2.50-1 ii libpulse0 5.0-2 ii librados2 0.80.1-2 ii librbd1 0.80.1-2 ii libsasl2-2 2.1.26.dfsg1-11 ii libsdl1.2debian 1.2.15-10 ii libseccomp2 2.1.1-1 ii libspice-server1 0.12.5-1 ii libssh2-1 1.4.3-3 ii libtinfo5 5.9+20140118-1 ii libusb-1.0-0 2:1.0.19-1 ii libusbredirparser1 0.7-1 ii libuuid1 2.20.1-5.8 ii libvdeplug2 2.3.2-4 ii libx11-6 2:1.6.2-2 ii libxen-4.3 4.3.0-3+b1 ii libxenstore3.0 4.3.0-3+b1 ii qemu-keymaps 2.0.0+dfsg-6 ii qemu-system-common 2.0.0+dfsg-6+b1 ii seabios 1.7.5-1 ii zlib1g 1:1.2.8.dfsg-1 Versions of packages qemu-system-x86 recommends: ii qemu-utils 2.0.0+dfsg-6+b1 Versions of packages qemu-system-x86 suggests: ii kmod 18-1 pn ovmf <none> pn samba <none> pn sgabios <none> pn vde2 <none> -- no debconf information -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org