CVE-2009-3616

NameCVE-2009-3616
SourceCVE (at NVD; RH)
DescriptionMultiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
NVD severityhigh
Debian Bugs553589, 553590
Debian/oldstablenot vulnerable
Debian/stablenot vulnerable
Debian/testingnot vulnerable
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
kvm (PTS)etch-backports28-4~bpo.1vulnerable
lenny, lenny (security)72+dfsg-5~lenny4fixed
squeeze (security)72+dfsg-5+squeeze1vulnerable
lenny-backports85+dfsg-4~bpo50+1vulnerable
experimental88+dfsg-3vulnerable
qemu (PTS)etch0.8.2-4etch2fixed
etch (security)0.8.2-4etch3fixed
lenny, lenny (security)0.9.1-10lenny1fixed
etch-backports0.9.1-10lenny1~bpo40+1vulnerable
squeeze, sid0.11.1-2fixed

The next table lists affected binary packages.

Binary PackageReleaseVersionStatusArchitecures
kvmetch-backports28-4~bpo.1vulnerableamd64, i386
lenny, lenny (security)72+dfsg-5~lenny4fixedamd64, i386
squeeze (security)72+dfsg-5+squeeze1vulnerableamd64, i386
kvm, kvm-dbglenny-backports85+dfsg-4~bpo50+1vulnerableamd64, i386
experimental88+dfsg-3vulnerableamd64, i386
kvm-sourceetch-backports28-4~bpo.1vulnerableall
lenny, lenny (security)72+dfsg-5~lenny4fixedall
squeeze72+dfsg-5vulnerableall
squeeze (security)72+dfsg-5+squeeze1vulnerableall
lenny-backports85+dfsg-4~bpo50+1vulnerableall
experimental88+dfsg-3vulnerableall
libqemu-dev, qemu, qemu-system, qemu-utilssid0.11.1-2fixedamd64, armel, i386, kfreebsd-amd64, kfreebsd-i386, powerpc, sparc
squeeze0.11.1-2fixedamd64, armel, i386, powerpc, sparc
qemuetch0.8.2-4etch2fixedamd64, i386, powerpc
etch (security)0.8.2-4etch3fixedamd64, i386, powerpc
etch-backports0.9.1-10lenny1~bpo40+1vulnerableamd64, i386, powerpc, sparc
lenny, lenny (security)0.9.1-10lenny1fixedamd64, i386, powerpc, sparc
qemu-user, qemu-user-staticsid, squeeze0.11.1-2fixedamd64, armel, i386, powerpc, sparc

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
kvmsource(unstable)(unfixed)medium553590
kvmsourcelenny(not affected)
qemusource(unstable)0.11.0-1medium553589
qemusourceetch(not affected)
qemusourcelenny(not affected)

Notes

[lenny] - qemu <not-affected> (Vulnerable code not present)
[etch] - qemu <not-affected> (Vulnerable code not present)
[lenny] - kvm <not-affected> (Vulnerable code not present)

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint