CVE-2015-5165, CVE-2015-5745, CVE-2015-5154, CVE-2015-5225 http://xenbits.xen.org/xsa/advisory-140.html http://seclists.org/oss-sec/2015/q3/302 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5154 https://lists.gnu.org/archive/html/qemu-devel/2015-08/msg02495.html
CVE-2015-5165 and CVE-2015-5154 http://www.vuxml.org/freebsd/f06f20dc-4347-11e5-93ad-002590263bf5.html http://www.vuxml.org/freebsd/da451130-365d-11e5-a4a5-002590263bf5.html emulators/qemu is still impacted and we still discussing the way ahead in 202402. The other ports have been fixed. CVE-2015-5225: In progress, https://reviews.freebsd.org/D3691 CVE-2015-5745: Looking into this one now.
(In reply to Jason Unovitch from comment #1) CVE-2015-5745: In emulators/qemu-devel 2.4.0 so this is mainly missing documentation along with discussion on emulators/qemu way ahead. https://github.com/qemu/qemu/commit/7882080388be5088e72c425b02223c02e6cb4295
Assign to maintainer. emulators/qemu now tracks the stable release. I'm unsure what we're goind to do with the -devel port.
Poudriere building.
A commit references this bug: Author: bofh Date: Fri Jan 1 17:54:10 UTC 2016 New revision: 405027 URL: https://svnweb.freebsd.org/changeset/ports/405027 Log: emulators/qemu-devel: Update version 2.4.0=>2.5.0 - Remove nox@ from MASTER_SITES (R.I.P. nox) - Take MAINTAINERSHIP - Add LICENSE (GPLv2) - Convert to OPTIONSNG - Fix patch files to be 'make makepatch' compatible - Fix Multiple Security Vulnerabilities [1] PR: 203112 [1] Submitted by: venture37@geeklan.co.uk [1] Security: CVE-2015-5165 [1] CVE-2015-5745 [1] CVE-2015-5154 [1] CVE-2015-5225 [1] Differential Revision: https://reviews.freebsd.org/D3691 Changes: head/emulators/qemu-devel/Makefile head/emulators/qemu-devel/distinfo head/emulators/qemu-devel/files/cdrom-dma-patch head/emulators/qemu-devel/files/hw_e1000_c.patch head/emulators/qemu-devel/files/patch-Makefile head/emulators/qemu-devel/files/patch-configure head/emulators/qemu-devel/files/patch-disas-libvixl-a64-disasm-a64.cc head/emulators/qemu-devel/files/patch-disas_libvixl_a64_disasm-a64.cc head/emulators/qemu-devel/files/patch-include-qemu-common.h head/emulators/qemu-devel/files/patch-include_net_net.h head/emulators/qemu-devel/files/patch-include_qemu-common.h head/emulators/qemu-devel/files/patch-net-tap-bsd.c head/emulators/qemu-devel/files/patch-net_tap-bsd.c head/emulators/qemu-devel/files/patch-qemu-char.c head/emulators/qemu-devel/files/patch-qemu-doc.texi head/emulators/qemu-devel/files/patch-qemu-include-net-net.h head/emulators/qemu-devel/files/patch-qemu-slirp-slirp_config.h head/emulators/qemu-devel/files/patch-slirp_slirp__config.h head/emulators/qemu-devel/files/patch-ui_x__keymap.c head/emulators/qemu-devel/files/patch-vl.c-serial head/emulators/qemu-devel/files/patch-x_keymap.c head/emulators/qemu-devel/files/pcap-patch head/emulators/qemu-devel/pkg-plist