Index: vuln.xml =================================================================== RCS file: /home/pcvs/ports/security/vuxml/vuln.xml,v retrieving revision 1.1738 diff -u -p -r1.1738 vuln.xml --- vuln.xml 1 Nov 2008 00:21:34 -0000 1.1738 +++ vuln.xml 2 Nov 2008 21:03:10 -0000 @@ -34,6 +34,39 @@ Note: Please add new entries to the beg --> + + qemu -- Heap overflow in Cirrus emulation + + + qemu + qemu-devel + 0.9.1_10 + 0.9.1s.20080101*0.9.1s.20080620_2 + + + + +

Aurelien Jarno reports:

+
+

CVE-2008-4539: fix a heap overflow in Cirrus emulation

+

The code in hw/cirrus_vga.c has changed a lot between + CVE-2007-1320 has been announced and the patch has been applied. + As a consequence it has wrongly applied and QEMU is still + vulnerable to this bug if using VNC.

+

(noticed by Jan Niehusmann)

+
+ +
+ + CVE-2008-4539 + http://lists.gnu.org/archive/html/qemu-devel/2008-10/msg01363.html + + + 2008-11-01 + 2008-11-02 + +
+ phpmyadmin -- Cross-Site Scripting Vulnerability