Several vulnerabilities have been discovered in the QEMU processor emulator. The Common Vulnerabilities and Exposures project identifies the following problems:
Ian Jackson discovered that range checks of file operations on emulated disk devices were insufficiently enforced.
It was discovered that an error in the format auto detection of removable media could lead to the disclosure of files in the host system.
A buffer overflow has been found in the emulation of the Cirrus graphics adaptor.
For the old stable distribution (etch), these problems have been fixed in version 0.8.2-4etch3.
For the stable distribution (lenny), these problems have been fixed in version 0.9.1-10lenny1.
For the unstable distribution (sid), these problems have been fixed in version 0.9.1+svn20081101-1.
We recommend that you upgrade your qemu packages.
MD5 checksums of the listed files are available in the original advisory.