You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa libvirt

Sigurnosni nedostatak programskog paketa libvirt

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2014-1090
2014-01-18 02:59:08
——————————————————————————–

Name : libvirt
Product : Fedora 19
Version : 1.0.5.9
Release : 1.fc19
URL : http://libvirt.org/
Summary : Library providing a simple virtualization API
Description :
Libvirt is a C toolkit to interact with the virtualization capabilities
of recent versions of Linux (and other OSes). The main package includes
the libvirtd server exporting the virtualization support.

——————————————————————————–
Update Information:

* Rebased to version 1.0.5.9
* Fix crash in virDBusAddWatch (bz #885445)
* Cleanup migration ports when migration is cancelled (bz #1018530)
* CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to libvirtd crash (bz #1054206, bz #1048631)
* CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters (bz #1049136, bz #1042252)
* CVE-2014-1447: libvirt: denial of service with keepalive (bz 1052957, bz 1054808)
——————————————————————————–
ChangeLog:

* Thu Jan 16 2014 Cole Robinson <crobinso@redhat.com> – 1.0.5.9-1
– Rebased to version 1.0.5.9
– Fix crash in virDBusAddWatch (bz #885445)
– Cleanup migration ports when migration is cancelled (bz #1018530)
– CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to
libvirtd crash (bz #1054206, bz #1048631)
– CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters (bz #1049136,
bz #1042252)
* Sat Dec 14 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.8-1
– Rebased to version 1.0.5.8
– Fix occasional libvirt-guests.service startup failure
– Fix return code of baselineCPU python API (bz #1033039)
– Don’t reload libvirt-guests when libvirt-client is updated (bz #962225)
– Fix infinite loop in libvirt_lxc (bz #1005570)
– Fix vdsm-tool segfault during vdsm startup (bz #1034312)
* Sun Nov 17 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.7-2
– Fix attaching ISO from cifs filesystem (bz #1012085)
– Fix crash with libxl driver and vcpu affinity (bz #1013045)
* Wed Nov 6 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.7-1
– Rebased to version 1.0.5.7
– Fix memory limit to not incorrectly invoke OOM killer on qemu (bz #966939)
* Sun Oct 6 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.6-3
– Fix virsh vol-resize (bz #1014874)
– Fix nwfilter crash during firewalld install (bz #1014933)
– Allow QoS change with update-device (bz #1014200)
* Tue Sep 24 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.6-2
– Fix snapshot restore when VM has disabled usb support (bz #1011520)
* Fri Sep 20 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.6-1
– Rebased to version 1.0.5.6
– Fix blockjobinfo python API (bz #999077)
– CVE-2013-4311: Insecure polkit usage (bz #1009539, bz #1005332)
– CVE-2013-4296: Invalid free memory stats (bz #1006173, bz #1009667)
– CVE-2013-4291: Supplementary groups handling (bz #1006509, bz #1006511)
– CVE-2013-5651: virBitmapParse out-of-bounds (bz #1006493)
– Fix virsh change-media with block disk type (bz #951192)
– Fix changing VNC listen address (bz #1006697)
* Thu Aug 1 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.5-1
– Rebased to version 1.0.5.5
– Really fix /dev/tty inside a container (bz #982317)
– Fix possible deadlock from getpwuid_r (bz #964358)
* Fri Jul 12 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.4-1
– Rebased to version 1.0.5.4
– Fix crash on migration
* Thu Jul 11 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.3-1
– Rebased to version 1.0.5.3
– Allow /dev/tty in LXC container (bz #982317)
– Fix cpu hot-add with latest qemu (bz #979260)
– Fix crash in udev logging (bz #969152)
* Wed Jun 12 2013 Cole Robinson <crobinso@redhat.com> – 1.0.5.2-1
– Rebased to version 1.0.5.2
– Don’t error if disk resize isn’t multiple of 512 (bz #951495)
– Fix racey cgroup error at VM startup (bz #965169)
– Fix crash in nwfilter at daemon shutdown (bz #967740)
– Fix ‘tray is locked’ error on media eject (bz #967914)
– Error on invalid combo of –tunnelled and –copy-storage (bz #968043)
——————————————————————————–
References:

[ 1 ] Bug #1018530 – qemu live migration port conflicts with other users of ephemeral port(s)
https://bugzilla.redhat.com/show_bug.cgi?id=1018530
[ 2 ] Bug #1054206 – CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to libvirtd crash [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1054206
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update libvirt’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorMarijo Plepelic
Cert idNCERT-REF-2014-01-0007-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Ranjivost progamskog paketa graphviz

Otkrivene su višestruke ranjivosti preljeva spremnika kod programskog paketa graphviz za Mandriva Business Server 1.0, Enterprise Server 5.0 izazvane greškom...

Close