QEMU: Multiple Vulnerabilities Multiple vulnerabilities have been found in QEMU, the worst of which could result in execution of arbitrary code or Denial of Service. qemu December 24, 2014 December 24, 2014: 1 528922 529030 531666 local, remote 2.1.2-r2 2.1.2-r2

QEMU is a generic and open source machine emulator and virtualizer.

Multiple vulnerabilities have been discovered in QEMU. Please review the CVE identifiers referenced below for details.

A context-dependent attacker may be able to execute arbitrary code, cause a Denial of Service condition, obtain sensitive information, or bypass security restrictions.

There is no known workaround at this time.

All QEMU users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-emulation/qemu-2.1.2-r2"
CVE-2014-3689 CVE-2014-7840 CVE-2014-8106 BlueKnight BlueKnight