Vulnerability Bulletins

DSA-3087 qemu - security update

   
Affected software Debian
 
Paolo Bonzini of Red Hat discovered that the blit region checks wereinsufficient in the Cirrus VGA emulator in qemu, a fast processoremulator. A privileged guest user could use this flaw to write into qemuaddress space on the host, potentially escalating their privileges tothose of the qemu host process.

More info:

https://www.debian.org/security/2014/dsa-3087