1
PublicDateAtUSN: 2008-05-12
3
Candidate: CVE-2008-2004
5
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2004
6
https://usn.ubuntu.com/usn/usn-776-1
8
The drive_init function in QEMU 0.9.1 determines the format of a raw disk
9
image based on the header, which allows local guest users to read arbitrary
10
files on the host by modifying the header to identify a different format,
11
which is used when the guest is restarted.
14
kees> xen-utils-3.x is in universe
15
mdeslaur> xen-qemu-block-no-auto-format.patch in RHEL5
22
vendor: http://patch-tracking.debian.net/patch/series/view/qemu/0.9.1-6/94_security.patch
23
upstream_qemu: needs-triage
24
dapper_qemu: ignored (reached end-of-life)
25
feisty_qemu: needed (reached end-of-life)
26
gutsy_qemu: needed (reached end-of-life)
27
hardy_qemu: ignored (reached end-of-life)
28
intrepid_qemu: not-affected
29
jaunty_qemu: not-affected
37
raring_qemu: not-affected
38
saucy_qemu: not-affected
39
trusty_qemu: not-affected
40
utopic_qemu: not-affected
41
vivid_qemu: not-affected
42
devel_qemu: not-affected
45
upstream_xen-3.0: needs-triage
47
feisty_xen-3.0: needs-triage (reached end-of-life)
67
vendor: http://people.ubuntu.com/~kees/qemu/xen-qemu-block-no-auto-format-CVE-2008-2004.patch
68
Tags_xen-3.1: universe-binary
69
upstream_xen-3.1: needs-triage
72
gutsy_xen-3.1: needed (reached end-of-life)
73
hardy_xen-3.1: ignored (reached end-of-life)
74
intrepid_xen-3.1: needed (reached end-of-life)
91
vendor: http://people.ubuntu.com/~kees/qemu/xen-qemu-block-no-auto-format-CVE-2008-2004.patch
92
Tags_xen-3.2: universe-binary
93
upstream_xen-3.2: needed
97
hardy_xen-3.2: ignored (reached end-of-life)
102
maverick_xen-3.2: DNE
115
vendor: http://people.ubuntu.com/~kees/qemu/xen-qemu-block-no-auto-format-CVE-2008-2004.patch
116
Tags_xen-3.3: universe-binary
117
upstream_xen-3.3: needed
122
intrepid_xen-3.3: needed (reached end-of-life)
123
jaunty_xen-3.3: ignored (reached end-of-life)
124
karmic_xen-3.3: ignored (reached end-of-life)
125
lucid_xen-3.3: ignored (reached end-of-life)
126
maverick_xen-3.3: ignored (reached end-of-life)
127
natty_xen-3.3: ignored (reached end-of-life)
139
upstream_kvm: released (0.72)
141
feisty_kvm: needed (reached end-of-life)
142
gutsy_kvm: needed (reached end-of-life)
143
hardy_kvm: released (1:62+dfsg-0ubuntu8.1)
144
intrepid_kvm: not-affected
145
jaunty_kvm: not-affected
161
upstream_qemu-kvm: needs-triage
164
intrepid_qemu-kvm: DNE
166
karmic_qemu-kvm: not-affected
167
lucid_qemu-kvm: not-affected
168
maverick_qemu-kvm: not-affected
169
natty_qemu-kvm: not-affected
170
oneiric_qemu-kvm: not-affected
171
precise_qemu-kvm: not-affected
172
quantal_qemu-kvm: not-affected