Rebuild with new bochs version. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-38212d42d8 2017-06-09 18:48:36.546624 --------------------------------------------------------------------------------Name : dolphin-emu Product : Fedora 26 Version : 5.0 Release : 14.fc26 URL : https://dolphin-emu.org/ Summary : GameCube / Wii / Triforce Emulator Description : Dolphin is a Gamecube, Wii and Triforce (the arcade machine based on the Gamecube) emulator, which supports full HD video with several enhancements such as compatibility with all PC controllers, turbo speed, networked multiplayer, and more. Most games run perfectly or with minor bugs. --------------------------------------------------------------------------------Update Information: Rebuild with new bochs version --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade dolphin-emu' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been discovered in Bochs, possibly allowing for the execution of arbitrary code or a Denial of Service.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200711-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Bochs: Multiple vulnerabilities Date: November 17, 2007 Bugs: #188148 ID: 200711-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in Bochs, possibly allowing for the execution of arbitrary code or a Denial of Service. Background ========= Bochs is a IA-32 (x86) PC emulator written in C++. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-emulation/bochs < 2.3 > = 2.3 Description ========== Tavis Ormandy of the Google Security Team discovered a heap-based overflow vulnerability in the NE2000 driver (CVE-2007-2893). He also discovered a divide-by-zero error in the emulated floppy disk controller (CVE-2007-2894). Impact ===== A local attacker in the guest operating system could exploit these issues to execute code outside of the virtual machine, or cause Bochs to crash. Workaround ========= There is no known workaround at this time. Resolution ========= All Bochs users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-emulation/bochs-2.3" References ========= [ 1 ] CVE-2007-2893 https://www.cve.org/CVERecord?id=CVE-2007-2893 [ 2 ] CVE-2007-2894 https://www.cve.org/CVERecord?id=CVE-2007-2894 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200711-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
This security update of bochs fixes CVE-2007-2894: The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of service (virtual machine crash) via unspecified vectors, resulting in a divide-by-zero error.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2007-1778 2007-08-23 22:41:20.530247 --------------------------------------------------------------------------------Name : bochs Product : Fedora 7 Version : 2.3 Release : 7.fc7 Summary : Portable x86 PC emulator Description : Bochs is a portable x86 PC emulation software package that emulates enough of the x86 CPU, related AT hardware, and BIOS to run DOS, Windows '95, Minix 2.0, and other OS's, all on your workstation. --------------------------------------------------------------------------------Update Information: This security update of bochs fixes CVE-2007-2894: The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of service (virtual machine crash) via unspecified vectors, resulting in a divide-by-zero error. --------------------------------------------------------------------------------ChangeLog: * Wed Aug 22 2007 Hans de Goede 2.3-7 - Fix CVE-2007-2894 (really fix bz 241799) * Sun Aug 5 2007 Hans de Goede 2.3-6 - Update License tag for new Licensing Guidelines compliance * Wed Jul 18 2007 Hans de Goede 2.3-5 - Fix CVE-2007-2893 (bz 241799) --------------------------------------------------------------------------------References: [ 1 ] Bug #241799 https://bugzilla.redhat.com/show_bug.cgi?id=241799 [ 2 ] CVE-2007-2894 --------------------------------------------------------------------------------Updated packages: ed353d54332640ce5e90454664496e5c3356be9a bochs-dlxlinux-2.3-7.fc7.ppc64.rpm fae7ed6e396f83b5f3ee154652c27839fc40ef9cbochs-gdb-2.3-7.fc7.ppc64.rpm 01aa04b4ee2ca81c56060d27a143c6932974b313 bochs-debugger-2.3-7.fc7.ppc64.rpm 06b46881ed957a141767ef8f385dc3b99563e923 bochs-debuginfo-2.3-7.fc7.ppc64.rpm 25121c686dd5f941b657c9da44a527c69b6b5f43 bochs-2.3-7.fc7.ppc64.rpm 1de6de5a69022b724811c053bd569f9eed87aa34 bochs-debuginfo-2.3-7.fc7.i386.rpm 88c8d43ec83a11a023334661523ea177a130fbe4 bochs-2.3-7.fc7.i386.rpm f5beeed5421182235e2831cb41b1420c02fd653f bochs-gdb-2.3-7.fc7.i386.rpm c307c52ca4674d7b7636f5e39358da2694a2dab0 bochs-dlxlinux-2.3-7.fc7.i386.rpm a9e3eb09e06bcf9fc536dc8845ea52d50bb860bd bochs-debugger-2.3-7.fc7.i386.rpm ed6b3aca82726d15db6b20bd5923d07da5f09855 bochs-debugger-2.3-7.fc7.x86_64.rpm d6be3cbe367589200e2563ba06f73e4e89f948a9 bochs-dlxlinux-2.3-7.fc7.x86_64.rpm c71c5b922211bb801dffbc69c58fca2b17c0a9f6 bochs-gdb-2.3-7.fc7.x86_64.rpm d425d5a249edf8fa66e0945506de733d705b3db8 bochs-2.3-7.fc7.x86_64.rpm f08e0dbfc2973dca985902da6884894386faf2fa bochs-debuginfo-2.3-7.fc7.x86_64.rpm 947d09e4a255477b8d0583597f5d81fb42f89e23 bochs-debuginfo-2.3-7.fc7.ppc.rpm a4d1bcef13b765d9b97112aff152923f822d48bf bochs-2.3-7.fc7.ppc.rpm 963385efed878cc4bab2849d0a94cc6afcd4845a bochs-gdb-2.3-7.fc7.ppc.rpm dba3eb9dc8cc49cfc7218c89957e380434c5b1a8 bochs-dlxlinux-2.3-7.fc7.ppc.rpm 6269d27e00e39bbfaed850fc0f504ae81aeab8a9 bochs-debugger-2.3-7.fc7.ppc.rpm 80701e12e85e27be621eef1f77c4b6933731c897 bochs-2.3-7.fc7.src.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Tavis Ormandy discovered that bochs, a highly portable IA-32 PC emulator, is vulnerable to a buffer overflow in the emulated NE2000 network device driver, which may lead to privilege escalation.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1351-1
Get the latest Linux and open source security news straight to your inbox.