Errata overview
Errata ID 243
Date 2019-08-28
Source package qemu
Fixed in version 1:2.8+dfsg-6+deb9u8A~4.4.1.201908270838
Description
This update addresses the following issues:
* device_tree: heap buffer overflow while loading device tree blob
  (CVE-2018-20815)
* qemu-bridge-helper ACL can be bypassed when names are too long
  (CVE-2019-13164)
* slirp: heap buffer overflow during packet reassembly (CVE-2019-14378)
Additional notes
CVE ID CVE-2018-20815
CVE-2019-13164
CVE-2019-14378
UCS Bug number #50059