<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="7abb948acb0b1ce068cda139837121ec"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="412">
  <id>dbg111-kvm</id>
  <title>kvm security update</title>
  <release>openSUSE 11.1</release>
  <issued date="1231723128"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=448551" id="448551" title="bug number 448551" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=464142" id="464142" title="bug number 464142" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=464141" id="464141" title="bug number 464141" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=252519" id="252519" title="bug number 252519" type="bugzilla"/>
  </references>
  <description>Rogue VNC clients could make the built in VNC server of kvm
run into an infinite loop (CVE-2008-2382)

An off-by-one bug limited the length of VNC passwords to
seven instead of eight (CVE-2008-5714)

Virtualized guests could potentially execute code on the
host by triggering a buffer overflow in the network
emulation code via large ethernet frames (CVE-2007-5729)

Virtualized guests could potentially execute code on the
host by triggering a heap based buffer overflow in the
Cirrus Graphics card emulation (CVE-2007-1320).
</description>
  <pkglist>
    <collection>
        <package name="kvm-debuginfo" arch="i586" version="78" release="6.5.1">
          <filename>kvm-debuginfo-78-6.5.1.i586.rpm</filename>
        </package>
        <package name="kvm-debuginfo" arch="x86_64" version="78" release="6.5.1">
          <filename>kvm-debuginfo-78-6.5.1.x86_64.rpm</filename>
        </package>
        <package name="kvm-debugsource" arch="i586" version="78" release="6.5.1">
          <filename>kvm-debugsource-78-6.5.1.i586.rpm</filename>
        </package>
        <package name="kvm-debugsource" arch="x86_64" version="78" release="6.5.1">
          <filename>kvm-debugsource-78-6.5.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
