oss-sec mailing list archives

Re: CVE-2015-1779 qemu: vnc: insufficient resource limiting in VNC websockets decoder


From: Petr Matousek <pmatouse () redhat com>
Date: Thu, 9 Apr 2015 16:30:44 +0200

On Tue, Mar 24, 2015 at 08:20:55AM +0100, Petr Matousek wrote:
Upstream patch submission:
https://lists.gnu.org/archive/html/qemu-devel/2015-03/msg04894.html

Upstream patches:

http://git.qemu.org/?p=qemu.git;a=commit;h=a2bebfd6e09d
http://git.qemu.org/?p=qemu.git;a=commit;h=2cdb5e142fb93

Please note that the first patch committed to QEMU project git is
slightly different than the initial submission as it includes fix
for a regression caused by the original patch.

Thanks,
-- 
Petr Matousek / Red Hat Product Security
PGP: 0xC44977CA 8107 AF16 A416 F9AF 18F3  D874 3E78 6F42 C449 77CA


Current thread: