qemu-stable
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-stable] [Qemu-devel] [ANNOUNCE] QEMU 1.5.2 Stable released


From: Daniel P. Berrange
Subject: Re: [Qemu-stable] [Qemu-devel] [ANNOUNCE] QEMU 1.5.2 Stable released
Date: Fri, 26 Jul 2013 11:09:39 +0100
User-agent: Mutt/1.5.21 (2010-09-15)

On Thu, Jul 25, 2013 at 04:44:43PM -0500, Michael Roth wrote:
> The QEMU v1.5.2 stable release is now available at:
> 
>   http://wiki.qemu.org/download/qemu-1.5.2.tar.bz2
> 
> This is release is solely to address a security issue (CVE-2013-2231) found
> in the QEMU Guest Agent on Windows. More details on the nature of the CVE
> can be found here:

It is fairly common to include the CVE number in the commit message subject
line as in this case, but sometimes people only put them in the body, or even
forgot completely. Other times you might not even realize the bug fixed was a
CVE until well after the commit is pushed to master.

So for libvirt we just started a policy of creating named tags for every
CVE fix [1], so you can just do  'git show CVE-2013-2231' and identify
the patch which fixed the issue. I mention this in case QEMU maintainers
think it might be a useful policy/approach for QEMU's GIT too.

Regards,
Daniel

[1] And retroactively tagged all previous fixes.
-- 
|: http://berrange.com      -o-    http://www.flickr.com/photos/dberrange/ :|
|: http://libvirt.org              -o-             http://virt-manager.org :|
|: http://autobuild.org       -o-         http://search.cpan.org/~danberr/ :|
|: http://entangle-photo.org       -o-       http://live.gnome.org/gtk-vnc :|



reply via email to

[Prev in Thread] Current Thread [Next in Thread]