Errata overview
Errata ID 567
Date 2019-08-28
Source package qemu
Fixed in version 1:2.8+dfsg-6+deb9u8A~4.3.4.20190827083
Description
This update addresses the following issues:
* device_tree: heap buffer overflow while loading device tree blob
  (CVE-2018-20815)
* qemu-bridge-helper ACL can be bypassed when names are too long
  (CVE-2019-13164)
* slirp: heap buffer overflow during packet reassembly (CVE-2019-14378)
Additional notes
CVE ID CVE-2018-20815
CVE-2019-13164
CVE-2019-14378
UCS Bug number #50063