Bug#742730: image format processing issues: lack of input validation

2014-05-14 Thread Michael Tokarev
Control: reopen -1 There are 2 more CVEs assigned to new issues found in qcow1 format processing. Since there's the same set of isssues, and since the relevant bug has only been closed for -testing anyway (and needs backporting to -stable and even maybe -oldstable), I'm adding them here. CVE-2014

Bug#742730: image format processing issues: lack of input validation

2014-03-26 Thread Michael Tokarev
Package: qemu, qemu-kvm Version: 1.1.2+dfsg-6 Severity: grave Tags: security patch upstream Several flaws were found in guest image format processing in qemu. CVEs are as follows: parallels: Sanity check for s->tracks (CVE-2014-0142) parallels: Fix catalog size integer overflow (CVE-2014-0143) qc