Summary: | emulators/qemu-devel: Multiple security vulnerabilities | ||
---|---|---|---|
Product: | Ports & Packages | Reporter: | Sevan Janiyan <venture37> |
Component: | Individual Port(s) | Assignee: | Muhammad Moinur Rahman <bofh> |
Status: | Closed FIXED | ||
Severity: | Affects Only Me | CC: | bofh, junovitch, ports-secteam, sbruno |
Priority: | --- | Keywords: | needs-patch, security |
Version: | Latest | Flags: | bofh:
maintainer-feedback+
|
Hardware: | Any | ||
OS: | Any |
Description
Sevan Janiyan
2015-09-15 00:44:51 UTC
CVE-2015-5165 and CVE-2015-5154 http://www.vuxml.org/freebsd/f06f20dc-4347-11e5-93ad-002590263bf5.html http://www.vuxml.org/freebsd/da451130-365d-11e5-a4a5-002590263bf5.html emulators/qemu is still impacted and we still discussing the way ahead in 202402. The other ports have been fixed. CVE-2015-5225: In progress, https://reviews.freebsd.org/D3691 CVE-2015-5745: Looking into this one now. (In reply to Jason Unovitch from comment #1) CVE-2015-5745: In emulators/qemu-devel 2.4.0 so this is mainly missing documentation along with discussion on emulators/qemu way ahead. https://github.com/qemu/qemu/commit/7882080388be5088e72c425b02223c02e6cb4295 Assign to maintainer. emulators/qemu now tracks the stable release. I'm unsure what we're goind to do with the -devel port. Poudriere building. A commit references this bug: Author: bofh Date: Fri Jan 1 17:54:10 UTC 2016 New revision: 405027 URL: https://svnweb.freebsd.org/changeset/ports/405027 Log: emulators/qemu-devel: Update version 2.4.0=>2.5.0 - Remove nox@ from MASTER_SITES (R.I.P. nox) - Take MAINTAINERSHIP - Add LICENSE (GPLv2) - Convert to OPTIONSNG - Fix patch files to be 'make makepatch' compatible - Fix Multiple Security Vulnerabilities [1] PR: 203112 [1] Submitted by: venture37@geeklan.co.uk [1] Security: CVE-2015-5165 [1] CVE-2015-5745 [1] CVE-2015-5154 [1] CVE-2015-5225 [1] Differential Revision: https://reviews.freebsd.org/D3691 Changes: head/emulators/qemu-devel/Makefile head/emulators/qemu-devel/distinfo head/emulators/qemu-devel/files/cdrom-dma-patch head/emulators/qemu-devel/files/hw_e1000_c.patch head/emulators/qemu-devel/files/patch-Makefile head/emulators/qemu-devel/files/patch-configure head/emulators/qemu-devel/files/patch-disas-libvixl-a64-disasm-a64.cc head/emulators/qemu-devel/files/patch-disas_libvixl_a64_disasm-a64.cc head/emulators/qemu-devel/files/patch-include-qemu-common.h head/emulators/qemu-devel/files/patch-include_net_net.h head/emulators/qemu-devel/files/patch-include_qemu-common.h head/emulators/qemu-devel/files/patch-net-tap-bsd.c head/emulators/qemu-devel/files/patch-net_tap-bsd.c head/emulators/qemu-devel/files/patch-qemu-char.c head/emulators/qemu-devel/files/patch-qemu-doc.texi head/emulators/qemu-devel/files/patch-qemu-include-net-net.h head/emulators/qemu-devel/files/patch-qemu-slirp-slirp_config.h head/emulators/qemu-devel/files/patch-slirp_slirp__config.h head/emulators/qemu-devel/files/patch-ui_x__keymap.c head/emulators/qemu-devel/files/patch-vl.c-serial head/emulators/qemu-devel/files/patch-x_keymap.c head/emulators/qemu-devel/files/pcap-patch head/emulators/qemu-devel/pkg-plist |