On Thu, Jul 25, 2013 at 04:44:43PM -0500, Michael Roth wrote: > The QEMU v1.5.2 stable release is now available at: > > http://wiki.qemu.org/download/qemu-1.5.2.tar.bz2 > > This is release is solely to address a security issue (CVE-2013-2231) found > in the QEMU Guest Agent on Windows. More details on the nature of the CVE > can be found here:
It is fairly common to include the CVE number in the commit message subject line as in this case, but sometimes people only put them in the body, or even forgot completely. Other times you might not even realize the bug fixed was a CVE until well after the commit is pushed to master. So for libvirt we just started a policy of creating named tags for every CVE fix [1], so you can just do 'git show CVE-2013-2231' and identify the patch which fixed the issue. I mention this in case QEMU maintainers think it might be a useful policy/approach for QEMU's GIT too. Regards, Daniel [1] And retroactively tagged all previous fixes. -- |: http://berrange.com -o- http://www.flickr.com/photos/dberrange/ :| |: http://libvirt.org -o- http://virt-manager.org :| |: http://autobuild.org -o- http://search.cpan.org/~danberr/ :| |: http://entangle-photo.org -o- http://live.gnome.org/gtk-vnc :|