Activity log for bug #213570

Date Who What changed Old value New value Message
2008-04-07 20:34:08 Jamie Strandboge bug added bug
2008-04-07 20:35:11 Jamie Strandboge kvm: importance Undecided High
2008-04-07 20:35:11 Jamie Strandboge kvm: assignee jamie-strandboge
2008-04-07 20:35:11 Jamie Strandboge kvm: status New Confirmed
2008-04-07 20:38:55 Jamie Strandboge description Binary package hint: kvm kvm uses qemu 0.9.1, and this version of qemu is vulnerable to several CVEs. Several of these were fixed in the Debian DSA: http://www.debian.org/security/2007/dsa-1284 This DSA fixes CVE-2007-1320, CVE-2007-1321, CVE-2007-1322, CVE-2007-1323. Please note that CVE-2007-1323 is a duplicate of CVE-2007-2893. Also note that CVE-2007-5729 and CVE-2007-5730 are referred to as CVE-2007-1321 in Debian. In addition to these fixes, qemu 0.9.1 is also vulnerable to CVE-2008-0928. Binary package hint: kvm kvm ships qemu 0.9.1 as part of its source code, and this version of qemu is vulnerable to several CVEs. Several of these were fixed in the Debian DSA: http://www.debian.org/security/2007/dsa-1284 This DSA fixes CVE-2007-1320, CVE-2007-1321, CVE-2007-1322, CVE-2007-1323. Please note that CVE-2007-1323 is a duplicate of CVE-2007-2893. Also note that CVE-2007-5729 and CVE-2007-5730 are referred to as CVE-2007-1321 in Debian. In addition to these fixes, qemu 0.9.1 is also vulnerable to CVE-2008-0928. Will provide a debdiff soon.
2008-04-07 20:44:51 Jamie Strandboge bug assigned to qemu (Ubuntu)
2008-04-07 20:47:03 Jamie Strandboge qemu: status New Invalid
2008-04-07 20:47:17 Jamie Strandboge qemu: status Invalid New
2008-04-07 22:07:07 Jamie Strandboge bug added attachment 'kvm_62+dfsg-0ubuntu3.debdiff' (kvm_62+dfsg-0ubuntu3.debdiff)
2008-04-07 23:48:30 Jamie Strandboge kvm: status Confirmed In Progress
2008-04-09 14:11:01 Jamie Strandboge kvm: status New Invalid
2008-04-09 14:11:39 Jamie Strandboge kvm: status New Invalid
2008-04-11 13:20:35 Jamie Strandboge kvm: status In Progress Fix Released
2008-07-29 13:32:38 Sergio Zanchetta qemu: status New Invalid
2008-08-25 17:12:56 Soren Hansen qemu: status New Fix Released
2008-08-25 17:12:56 Soren Hansen qemu: statusexplanation
2008-08-26 16:53:26 Jamie Strandboge kvm: status New Fix Released
2008-08-26 16:53:26 Jamie Strandboge kvm: statusexplanation
2008-09-09 18:39:15 Jorge Castro bug assigned to kvm (Fedora)
2008-09-10 13:49:10 Bug Watch Updater kvm: status Unknown Fix Released
2008-12-15 02:37:57 Hew kvm: status New Won't Fix
2008-12-15 02:37:57 Hew kvm: statusexplanation Ubuntu Feisty Fawn is no longer supported, so a SRU will not be issued for this release. Marking Feisty as Won't Fix.
2008-12-15 02:38:11 Hew qemu: status New Won't Fix
2008-12-15 02:38:11 Hew qemu: statusexplanation
2009-01-24 15:44:00 Jamie Strandboge bug added subscriber Ubuntu Security Team
2009-01-30 21:11:24 Jamie Strandboge kvm: status New Confirmed
2009-01-30 21:11:30 Jamie Strandboge qemu: status New Confirmed
2009-01-30 21:11:34 Jamie Strandboge qemu: status New Confirmed
2009-01-30 21:18:15 Jamie Strandboge qemu: status New Fix Released
2009-01-30 21:18:15 Jamie Strandboge qemu: statusexplanation
2009-05-07 13:00:05 Sergio Zanchetta kvm (Ubuntu Gutsy): status Confirmed Won't Fix
2009-05-07 13:00:15 Sergio Zanchetta qemu (Ubuntu Gutsy): status Confirmed Won't Fix
2010-08-26 13:14:38 Jamie Strandboge qemu (Ubuntu Dapper): status Confirmed Won't Fix
2017-10-26 20:24:50 Bug Watch Updater kvm (Fedora): importance Unknown High
2017-10-26 20:57:14 Hew removed subscriber Hew McLachlan