Package : bochs
Vulnerability : buffer overflow
Problem type : local
Debian-specific: no
CVE ID : CVE-2007-2893
Tavis Ormandy discovered that bochs, a highly portable IA-32 PC emulator,
is vulnerable to a buffer overflow in the emulated NE2000 network device
driver, which may lead to privilege escalation.
For the oldstable distribution (sarge) this problem has been fixed in
version 2.1.1+20041109-3sarge1.
For the stable distribution (etch) this problem has been fixed in
version 2.3-2etch1.
For the unstable distribution (sid) this problem has been fixed in
version 2.3+20070705-1.
We recommend that you upgrade your bochs packages.
Upgrade Instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given at the end of this advisory:
--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Tue Aug 7 17:26:58 2007
This archive was generated by hypermail 2.1.8
: Thu Aug 09 2007 - 19:06:12 EDT