-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 30 Jan 2020 23:28:55 +0300 Source: qemu Architecture: source Version: 1:3.1+dfsg-8+deb10u4 Distribution: buster-security Urgency: medium Maintainer: Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org> Changed-By: Michael Tokarev <mjt@tls.msk.ru> Closes: 939869 946210 949731 Changes: qemu (1:3.1+dfsg-8+deb10u4) buster-security; urgency=medium . * acknowledge the last NMU by the Security Team * io-ensure-UNIX-client-doesn-t-unlink-server-socket.patch Closes: #946210 * slirp possible use-after-free in ip_reass(), slirp-ip_reass-fix-use-after-free-CVE-CVE-2019-15890.patch Closes: #939869, CVE-2019-15890 * slirp emulation fixes, Closes: CVE-2020-7039 tcp_emu-fix-OOB-access-CVE-2020-7039.patch slirp-use-correct-size-while-emulating-commands-CVE-2020-7039.patch slirp-use-correct-size-while-emulating-IRC-commands-CVE-2020-7039.patch * fix iscsi OOB heap access via an unexpected response of iSCSI Server, scsi-cap-block-count-from-GET-LBA-STATUS-CVE-2020-1711.patch Closes: #949731, CVE-2020-1711 Checksums-Sha1: 028fd422ddfaf6168cc097b32c4a564169645ca7 6152 qemu_3.1+dfsg-8+deb10u4.dsc e8efd819cde6e6a7ab8e2863fe8c3b73c5530271 92988 qemu_3.1+dfsg-8+deb10u4.debian.tar.xz 10247d18009b29dbe749fcd1f97b2710ab754df4 8582 qemu_3.1+dfsg-8+deb10u4_source.buildinfo Checksums-Sha256: af990e2ec4e6ae2cf0f040caa17576fa7f76e06f938ededc30abc691e87c576b 6152 qemu_3.1+dfsg-8+deb10u4.dsc c5b61b5b45eaa3aff59206683d5a746ab642d6b167f6fb40dd774f847c3dccb3 92988 qemu_3.1+dfsg-8+deb10u4.debian.tar.xz 33a4e68fa15293c7616ac9471a17c0c5b3c2a90493687f3a65897ebd9fd57265 8582 qemu_3.1+dfsg-8+deb10u4_source.buildinfo Files: df1d70ca07192cff805e474736b34d32 6152 otherosfs optional qemu_3.1+dfsg-8+deb10u4.dsc a3b6ad75647ea6f9a58a079e8783da0b 92988 otherosfs optional qemu_3.1+dfsg-8+deb10u4.debian.tar.xz 535cdc2038bc4ea4bd3a263eb9ade7e4 8582 otherosfs optional qemu_3.1+dfsg-8+deb10u4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQFDBAEBCAAtFiEEe3O61ovnosKJMUsicBtPaxppPlkFAl40CCsPHG1qdEB0bHMu bXNrLnJ1AAoJEHAbT2saaT5ZaSIH/1CqlfrmtNBukHWUiqv6W4nU3P4cBdd2WJNz pmLKalSF40dq1XNYiKQCRNlXFBFF4SycPahywiIWHoEsp873GZnGuAu383CvpDS8 xICeDudQBOC2EIZaRqfoSQSypg5VUz6RxLSUOrcjGvNwtWxA3gXPNKAnVNQBdJ+a Ggd+RQjfyDxWlnqJvX52f9ySVd76zj8xPo9H3oL6++RT1qy8PGfJsRhWNcALaOR6 LbRW29lAQOonp2Ggr+05cX3YFyu0ELnV4cHX5S8EWw1uW3fMM9NlSTbrcHVC6EJg iDPQMe198U8k6zVvc846c4JT4n9QMq3aAz0efVsma+qTqGobz34= =yicp -----END PGP SIGNATURE-----