Merge lp://qastaging/~brightbox/ubuntu/maverick/qemu-kvm/qemu-kvm.fix-697197 into lp://qastaging/ubuntu/maverick/qemu-kvm

Proposed by Neil Wilson
Status: Needs review
Proposed branch: lp://qastaging/~brightbox/ubuntu/maverick/qemu-kvm/qemu-kvm.fix-697197
Merge into: lp://qastaging/ubuntu/maverick/qemu-kvm
Diff against target: 109 lines (+72/-1)
5 files modified
debian/changelog (+19/-0)
debian/control (+1/-1)
debian/patches/697197-fix-vnc-password-semantics.patch (+17/-0)
debian/patches/caps-lock-key-up-event.patch (+33/-0)
debian/patches/series (+2/-0)
To merge this branch: bzr merge lp://qastaging/~brightbox/ubuntu/maverick/qemu-kvm/qemu-kvm.fix-697197
Reviewer Review Type Date Requested Status
Dustin Kirkland  Approve
Review via email: mp+47820@code.qastaging.launchpad.net

Description of the change

Security fix for CVE 2011-0011

To post a comment you must log in.
Revision history for this message
Dustin Kirkland  (kirkland) wrote :

Looks good, thanks for doing this, Neil.

I'm going to update it just slightly, as this debdiff will need to go through the security queue, since there's an associated CVE. I'll prep that upload and the security team will sponsor it into maverick-security.

I'll get it uploaded to natty now.

The last thing I need you to do is to email your patch to the qemu-devel mailing list. The maintainers do not accept patches solely attached to bugs in Launchpad. Their processes require that you email the patch to the mailing list. Sorry for the run-around. Cheers!

review: Approve
Revision history for this message
Neil Wilson (neil-aldur) wrote :

Dustin,

I've been following the discussion on the qemu development list and
they are going for a complete rewrite of the associated functions to
get rid of the overloaded behaviour. There's an ongoing discussion
with the RedHat boys about it.

Additionally I think this patch needs to go into Lucid as well.

On 11 February 2011 15:39, Dustin Kirkland <email address hidden> wrote:
> Review: Approve
> Looks good, thanks for doing this, Neil.
>
> I'm going to update it just slightly, as this debdiff will need to go through the security queue, since there's an associated CVE.  I'll prep that upload and the security team will sponsor it into maverick-security.
>
> I'll get it uploaded to natty now.
>
> The last thing I need you to do is to email your patch to the qemu-devel mailing list.  The maintainers do not accept patches solely attached to bugs in Launchpad.  Their processes require that you email the patch to the mailing list.  Sorry for the run-around.  Cheers!
> --
> https://code.launchpad.net/~brightbox/ubuntu/maverick/qemu-kvm/qemu-kvm.fix-697197/+merge/47820
> Your team Brightbox is subscribed to branch lp:~brightbox/ubuntu/maverick/qemu-kvm/qemu-kvm.fix-697197.
>

--
Neil Wilson

Revision history for this message
Dustin Kirkland  (kirkland) wrote :

On Fri, Feb 11, 2011 at 9:49 AM, Neil Wilson <email address hidden> wrote:
> I've been following the discussion on the qemu development list and
> they are going for a complete rewrite of the associated functions to
> get rid of the overloaded behaviour. There's an ongoing discussion
> with the RedHat boys about it.
>
> Additionally I think this patch needs to go into Lucid as well.

Thanks, I ported the debdiff for lucid-security too.

I can't follow the qemu-devel list in detail any more. Would you mind
just dropping me a note once they get their fixes for this issue in
git HEAD?

Cheers,
Dustin

Revision history for this message
Neil Wilson (neil-aldur) wrote :

On 11 February 2011 16:07, Dustin Kirkland <email address hidden> wrote:

> Thanks, I ported the debdiff for lucid-security too.
>
> I can't follow the qemu-devel list in detail any more.  Would you mind
> just dropping me a note once they get their fixes for this issue in
> git HEAD?
>
> Cheers,
> Dustin

Will do.

It may take some time to resolve - a few differences of opinion to
iron out as ever.

--
Neil Wilson

Unmerged revisions

97. By Neil Wilson

Add patch description.

96. By Neil Wilson

* SECURITY UPDATE: Setting VNC password to empty string silently
  disables all authentication (LP: #697197)
  - debian/patches/697197-fix-vnc-password-semantics.patch: Reverses the
  change introduced in Qemu by git commit 52c18be9
  CVE: 2011-0011

95. By Benjamin Drung

Add caps-lock-key-up-event.patch to enable normal up/down events for
Caps-Lock and Num-Lock keys by setting SDL_DISABLE_LOCK_KEYS (which
requires SDL > 1.2.14). This fixes handling of capslock when capslock is
mapped to something else in host system. (LP: #427612)

Preview Diff

[H/L] Next/Prev Comment, [J/K] Next/Prev File, [N/P] Next/Prev Hunk
The diff is not available at this time. You can reload the page or download it.

Subscribers

People subscribed via source and target branches