Ubuntu has issued an advisory on January 30: http://www.ubuntu.com/usn/usn-2092-1/ This issue was *not* fixed in 1.6.2, though the release announcement is here: http://lists.nongnu.org/archive/html/qemu-stable/2013-12/msg00148.html It was, however, fixed in this Fedora commit with patches 106-116: http://pkgs.fedoraproject.org/cgit/qemu.git/commit/?h=f20&id=2983660f65e196adaefdadc807effe9c1af85cb3 The version in Mageia 3 is too old to be affected, so only Mageia 4 is. Reproducible: Steps to Reproduce:
Whiteboard: (none) => MGA4TOO
Updated and patched packages uploaded for Mageia 4 and Cauldron. Advisory: ======================== Updated qemu packages fix security vulnerability: Sibiao Luo discovered that QEMU incorrectly handled device hot-unplugging. A local user could possibly use this flaw to cause a denial of service (CVE-2013-4377). Additionally, qemu has been updated to 1.6.2, fixing several other bugs. References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4377 http://lists.nongnu.org/archive/html/qemu-stable/2013-12/msg00148.html http://www.ubuntu.com/usn/usn-2092-1/ ======================== Updated packages in core/updates_testing: ======================== qemu-1.6.2-1.mga4 qemu-img-1.6.2-1.mga4 from qemu-1.6.2-1.mga4
Version: Cauldron => 4Assignee: bugsquad => qa-bugsWhiteboard: MGA4TOO => (none)
Testing procedure: https://bugs.mageia.org/show_bug.cgi?id=6694#c3
CC: (none) => stormiWhiteboard: (none) => has_procedure
Testing complete on Mageia 4 i586, following the procedure linked in comment 2. No regressions found.
CC: (none) => remiWhiteboard: has_procedure => has_procedure MGA4-32-OK
Using above procedure, everything ok. Someone with commit right can upload advisory and validate.
Whiteboard: has_procedure MGA4-32-OK => has_procedure MGA4-32-OK MGA4-64-OK
Hardware: i586 => All
Validating update. Advisory uploaded, could a sysadmin push the update to core/updates for Mageia 4? Thanks!
Keywords: (none) => validated_updateWhiteboard: has_procedure MGA4-32-OK MGA4-64-OK => has_procedure MGA4-32-OK MGA4-64-OK advisoryCC: (none) => sysadmin-bugs
Update pushed: http://advisories.mageia.org/MGASA-2014-0060.html
Status: NEW => RESOLVEDCC: (none) => tmbResolution: (none) => FIXED