[prev in list] [next in list] [prev in thread] [next in thread] 

List:       qubes-devel
Subject:    [qubes-devel] Re: Qubes Security Bulletin #23
From:       Vít_Šesták <groups-no-private-mail--contact-me-at--co
Date:       2015-12-19 12:57:04
Message-ID: 13ddc626-4126-4ef1-af0c-469c52a2b3f4 () googlegroups ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


The QSB is very detailed, but I am not sure if I have correctly extracted 
the conclusion: It potentially allows attack from NetVM (or maybe even 
FirewallVM or ProxyVM?) to some AppVM. Is that correct?

Regards,
Vít Šesták 'v6ak'

On Thursday, December 17, 2015 at 1:19:12 PM UTC+1, Joanna Rutkowska wrote:
> 
> -----BEGIN PGP SIGNED MESSAGE----- 
> Hash: SHA256 
> 
> Dear Qubes users, 
> 
> We have just released a new Qubes Security Bulletin (QSB #23): 
> 
> https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-023-2015.txt 
> 
> Regards, 
> joanna. 
> 
> - -- 
> The Qubes Security Team 
> https://qubes-os.org/doc/SecurityPage/ 
> -----BEGIN PGP SIGNATURE----- 
> 
> iQIcBAEBCAAGBQJWcqg1AAoJEDOT2L8N3GcYzT0P/RnkctuokzCN5WMy4eVn7UzK 
> ZfOr5LwFHBkGLGNzG+LQfg4hb4p8aJ3KLPkIJUWgDs1pcnXCjb1YstXzSU0ViOy6 
> 6rXcbv6SPQr/izsylsZKJcx8XnQGhDKk+qHsRvfq4KNICNNM1WN0CCzRX8BHH5CI 
> HLyEoC0carWXtZFfue3OBiz42dgABmWnkJFfYhFf68knWenUWga4FTJ5KhsrqK+k 
> f/XSzAETtNcvk/6qlj3HBsJJ26v9t3TdOisLE4VNNUx4CSwqhZoEhYZKx37cYtJf 
> BNv2AHfs6xzHP82/6BohNbJP7asZcipFl5i5aGoY/6w/wYFGupRQf2cRXX07+HBQ 
> WG42F5hLO4YTSzKk7yK9JmbrGX/aCnLVW92wVL9XEgVGkROdY0p2hoJLJrMKIUO/ 
> WP/tx+pHvcILbPspM1X/Qut2+L7Ld33WznHDIX1EQyS8DUQ89hVOW9n9wn9uM1l1 
> wZ97Ph6Z8odboKW1C9FLBMOb6Z8F3qucVGCdAwoHZncEnmEklCTZ9izkq9KDFvHZ 
> LILidncgBWoiSFo+X4q4fBqmmIPs6ZXRCvBRy9Hq30jcqLaO3mEH0/eqdDdsRabb 
> xv1W9lOFFQDxR5H78u6UyTRAvCN+1a2dvZXIMN7XaAsDeQSXBwUgK87hfF+jOdvv 
> BZbjliwFNmikXlgJc5Zw 
> =2WUp 
> -----END PGP SIGNATURE----- 
> 

-- 
You received this message because you are subscribed to the Google Groups \
"qubes-devel" group. To unsubscribe from this group and stop receiving emails from \
it, send an email to qubes-devel+unsubscribe@googlegroups.com. To post to this group, \
send email to qubes-devel@googlegroups.com. To view this discussion on the web visit \
https://groups.google.com/d/msgid/qubes-devel/13ddc626-4126-4ef1-af0c-469c52a2b3f4%40googlegroups.com.
 For more options, visit https://groups.google.com/d/optout.


[Attachment #5 (text/html)]

<div dir="ltr">The QSB is very detailed, but I am not sure if I have correctly \
extracted the conclusion: It potentially allows attack from NetVM (or maybe even \
FirewallVM or ProxyVM?) to some AppVM. Is that correct?<br><br>Regards,<br>Vít Š\
esták &#39;v6ak&#39;<br><br>On Thursday, December 17, 2015 at 1:19:12 PM UTC+1, \
Joanna Rutkowska wrote:<blockquote class="gmail_quote" style="margin: 0;margin-left: \
0.8ex;border-left: 1px #ccc solid;padding-left: 1ex;">-----BEGIN PGP SIGNED \
MESSAGE----- <br>Hash: SHA256
<br>
<br>Dear Qubes users,
<br>
<br>We have just released a new Qubes Security Bulletin (QSB #23):
<br>
<br><a href="https://github.com/QubesOS/qubes-secpack/blob/master/QSBs/qsb-023-2015.txt" \
target="_blank" rel="nofollow" \
onmousedown="this.href=&#39;https://www.google.com/url?q\75https%3A%2F%2Fgithub.com%2F \
QubesOS%2Fqubes-secpack%2Fblob%2Fmaster%2FQSBs%2Fqsb-023-2015.txt\46sa\75D\46sntz\0751\46usg\75AFQjCNFXz3SmUIXiP6ilEp8AqqH6jtWRqQ&#39;;return \
true;" onclick="this.href=&#39;https://www.google.com/url?q\75https%3A%2F%2Fgithub.com \
%2FQubesOS%2Fqubes-secpack%2Fblob%2Fmaster%2FQSBs%2Fqsb-023-2015.txt\46sa\75D\46sntz\0751\46usg\75AFQjCNFXz3SmUIXiP6ilEp8AqqH6jtWRqQ&#39;;return \
true;">https://github.com/QubesOS/<wbr>qubes-secpack/blob/master/<wbr>QSBs/qsb-023-2015.txt</a>
 <br>
<br>Regards,
<br>joanna.
<br>
<br>- --
<br>The Qubes Security Team
<br><a href="https://qubes-os.org/doc/SecurityPage/" target="_blank" rel="nofollow" \
onmousedown="this.href=&#39;https://www.google.com/url?q\75https%3A%2F%2Fqubes-os.org% \
2Fdoc%2FSecurityPage%2F\46sa\75D\46sntz\0751\46usg\75AFQjCNG7q34PWSUbdXDxYdEvaD4TiIK2DA&#39;;return \
true;" onclick="this.href=&#39;https://www.google.com/url?q\75https%3A%2F%2Fqubes-os.o \
rg%2Fdoc%2FSecurityPage%2F\46sa\75D\46sntz\0751\46usg\75AFQjCNG7q34PWSUbdXDxYdEvaD4TiIK2DA&#39;;return \
true;">https://qubes-os.org/doc/<wbr>SecurityPage/</a> <br>-----BEGIN PGP \
SIGNATURE----- <br>
<br>iQIcBAEBCAAGBQJWcqg1AAoJEDOT2L<wbr>8N3GcYzT0P/<wbr>RnkctuokzCN5WMy4eVn7UzK
<br>ZfOr5LwFHBkGLGNzG+<wbr>LQfg4hb4p8aJ3KLPkIJUWgDs1pcnXC<wbr>jb1YstXzSU0ViOy6
<br>6rXcbv6SPQr/<wbr>izsylsZKJcx8XnQGhDKk+<wbr>qHsRvfq4KNICNNM1WN0CCzRX8BHH5C<wbr>I
<br>HLyEoC0carWXtZFfue3OBiz42dgABm<wbr>WnkJFfYhFf68knWenUWga4FTJ5Khsr<wbr>qK+k
<br>f/XSzAETtNcvk/<wbr>6qlj3HBsJJ26v9t3TdOisLE4VNNUx4<wbr>CSwqhZoEhYZKx37cYtJf
<br>BNv2AHfs6xzHP82/<wbr>6BohNbJP7asZcipFl5i5aGoY/6w/<wbr>wYFGupRQf2cRXX07+HBQ
<br>WG42F5hLO4YTSzKk7yK9JmbrGX/<wbr>aCnLVW92wVL9XEgVGkROdY0p2hoJLJ<wbr>rMKIUO/
<br>WP/tx+pHvcILbPspM1X/Qut2+<wbr>L7Ld33WznHDIX1EQyS8DUQ89hVOW9n<wbr>9wn9uM1l1
<br>wZ97Ph6Z8odboKW1C9FLBMOb6Z8F3q<wbr>ucVGCdAwoHZncEnmEklCTZ9izkq9KD<wbr>FvHZ
<br>LILidncgBWoiSFo+<wbr>X4q4fBqmmIPs6ZXRCvBRy9Hq30jcqL<wbr>aO3mEH0/eqdDdsRabb
<br>xv1W9lOFFQDxR5H78u6UyTRAvCN+<wbr>1a2dvZXIMN7XaAsDeQSXBwUgK87hfF<wbr>+jOdvv
<br>BZbjliwFNmikXlgJc5Zw
<br>=2WUp
<br>-----END PGP SIGNATURE-----
<br></blockquote></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups \
&quot;qubes-devel&quot; group.<br /> To unsubscribe from this group and stop \
receiving emails from it, send an email to <a \
href="mailto:qubes-devel+unsubscribe@googlegroups.com">qubes-devel+unsubscribe@googlegroups.com</a>.<br \
/> To post to this group, send email to <a \
href="mailto:qubes-devel@googlegroups.com">qubes-devel@googlegroups.com</a>.<br /> To \
view this discussion on the web visit <a \
href="https://groups.google.com/d/msgid/qubes-devel/13ddc626-4126-4ef1-af0c-469c52a2b3 \
f4%40googlegroups.com?utm_medium=email&utm_source=footer">https://groups.google.com/d/ \
msgid/qubes-devel/13ddc626-4126-4ef1-af0c-469c52a2b3f4%40googlegroups.com</a>.<br /> \
For more options, visit <a \
href="https://groups.google.com/d/optout">https://groups.google.com/d/optout</a>.<br \
/>

------=_Part_2852_595655643.1450529824845--



[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic