[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] [PATCH] Fix CVE-2007-1320, CVE-2007-1321 , CVE-2007-1322, CVE-2007-1323 and CVE-2007-1366


  • To: <caglar@xxxxxxxxxxxxx>, <xen-devel@xxxxxxxxxxxxxxxxxxx>
  • From: Keir Fraser <keir@xxxxxxxxxxxxx>
  • Date: Tue, 01 May 2007 14:44:38 +0100
  • Delivery-date: Tue, 01 May 2007 06:43:25 -0700
  • List-id: Xen developer discussion <xen-devel.lists.xensource.com>
  • Thread-index: AceL9txxGySIRffqEduxNAAX8io7RQ==
  • Thread-topic: [Xen-devel] [PATCH] Fix CVE-2007-1320, CVE-2007-1321 , CVE-2007-1322, CVE-2007-1323 and CVE-2007-1366

On 1/5/07 14:29, "S.ÃaÄlar Onur" <caglar@xxxxxxxxxxxxx> wrote:

> If anybody interested, attached patch (against 3.0.4) fixes CVE-2007-1320,
> CVE-2007-1321 , CVE-2007-1322, CVE-2007-1323 and CVE-2007-1366 which affects
> qemu and also seems valid for xen.

Is the patch from upstream qemu? We have our own patches to fix these issues
in 3.0.5-rc, but we'd consider an alternative that keeps us closer to
upstream qemu (albeit a later qemu than we build against).

 -- Keir


_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.