You are here
Home > Preporuke > Ranjivost programske biblioteke libvirt

Ranjivost programske biblioteke libvirt

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-1892
2015-02-09 02:09:29
——————————————————————————–

Name : libvirt
Product : Fedora 21
Version : 1.2.9.2
Release : 1.fc21
URL : http://libvirt.org/
Summary : Library providing a simple virtualization API
Description :
Libvirt is a C toolkit to interact with the virtualization capabilities
of recent versions of Linux (and other OSes). The main package includes
the libvirtd server exporting the virtualization support.

——————————————————————————–
Update Information:

* Rebased to version 1.2.9.2
* CVE-2014-8131: deadlock and segfault in qemuConnectGetAllDomainStats (bz #1172571)
* CVE-2015-0236: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects (bz #1185769)
* CVE-2014-8136: local denial of service in qemu/qemu_driver.c (bz #1176179)
* Fix crash parsing nbd URIs (bz #1188644)
* Fix domain startup failing with ‘strict’ mode in numatune (bz #1168672)
——————————————————————————–
ChangeLog:

* Sat Feb 7 2015 Cole Robinson <crobinso@redhat.com> – 1.2.9.2-1
– Rebased to version 1.2.9.2
– CVE-2014-8131: deadlock and segfault in qemuConnectGetAllDomainStats (bz
– CVE-2015-0236: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save
images and snapshots objects (bz #1185769)
– CVE-2014-8136: local denial of service in qemu/qemu_driver.c (bz #1176179)
– Fix crash parsing nbd URIs (bz #1188644)
– Fix domain startup failing with ‘strict’ mode in numatune (bz #1168672)
* Tue Dec 2 2014 Cole Robinson <crobinso@redhat.com> – 1.2.9.1-2
– Don’t reject aarch64 + uefi
——————————————————————————–
References:

[ 1 ] Bug #1172569 – CVE-2014-8131 libvirt: deadlock and segfault in qemuConnectGetAllDomainStats
https://bugzilla.redhat.com/show_bug.cgi?id=1172569
[ 2 ] Bug #1184431 – CVE-2015-0236 libvirt: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects
https://bugzilla.redhat.com/show_bug.cgi?id=1184431
[ 3 ] Bug #1176176 – CVE-2014-8136 libvirt: local denial of service in qemu/qemu_driver.c
https://bugzilla.redhat.com/show_bug.cgi?id=1176176
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update libvirt’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

 

 

 

 

——————————————————————————–
Fedora Update Notification
FEDORA-2015-1883
2015-02-09 02:09:05
——————————————————————————–

Name : libvirt
Product : Fedora 20
Version : 1.1.3.9
Release : 1.fc20
URL : http://libvirt.org/
Summary : Library providing a simple virtualization API
Description :
Libvirt is a C toolkit to interact with the virtualization capabilities
of recent versions of Linux (and other OSes). The main package includes
the libvirtd server exporting the virtualization support.

——————————————————————————–
Update Information:

* Rebased to version 1.1.3.9
* CVE-2015-0236: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects (bz #1185769)
* CVE-2014-8136: local denial of service in qemu/qemu_driver.c (bz #1176179)
——————————————————————————–
ChangeLog:

* Sat Feb 7 2015 Cole Robinson <crobinso@redhat.com> – 1.1.3.9-1
– Rebased to version 1.1.3.9
– CVE-2015-0236: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save
images and snapshots objects (bz #1185769)
– CVE-2014-8136: local denial of service in qemu/qemu_driver.c (bz #1176179)
* Sat Nov 15 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.8-1
– Rebased to version 1.1.3.8
– CVE-2014-3633: out-of-bounds read in blockiotune (bz #1160823)
– CVE-2014-3657: Potential deadlock in domain_conf (bz #1160824)
– CVE-2014-7823: information leak with migratable flag (bz #1160822)
* Thu Oct 30 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.6-2
– Fix USB device descriptions (bz #1138887)
* Mon Sep 8 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.6-1
– Rebased to version 1.1.3.6
– Fix memory leak in testDomainGenerateIfnames (bz 1135388)
– Fix python bindings graphics event enum (bz 1113612)
– Fix cflags in pkg-config –libs (bz 1134453)
– Fix pci bus naming for PPC (bz 1119401)
– Fix LXC user namespacess (bz 1105832)
– Fix possible ‘unknown error’ reporting from vol-dumpxml (bz 1097067)
* Mon May 19 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.5-2
– Fix xen hvm VNC port (bz #1094262)
– CVE-2014-0179: Unsafe XML parsing (bz #1094792, bz #1088290)
– Fix failure to start xen instances (rackspace in particular) (bz #1098376)
* Sat May 3 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.5-1
– Rebased to version 1.1.3.5
– Fix QXL PCI address conflict (bz #1016775)
– Fix journald PRIORITY values (bz #1043550)
– Fix crash with filterref and update-device (bz #1093301)
– Fix ‘cannot find session’ error with iscsi (bz #1093791)
– Fix bond XML issues (bz #1084702)
* Tue Mar 18 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.4-4
– Fix migration failure occurring with VIR_DOMAIN_XML_MIGRATABLE (bz #1075174)
* Mon Mar 10 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.4-3
– Escape XML characters in volume XML (bz #1074528)
* Wed Mar 5 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.4-2
– Fix libvirt-guests.service on host boot (bz #1031696)
* Tue Feb 18 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.4-1
– Rebased to version 1.1.3.4
– Fix domain events when ACLs are used (bz #1058839)
– CVE-2013-6456: unsafe usage of paths under /proc//root (bz #1048628, bz
* Sat Feb 1 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.3-5
– Rebuild again for openwsman soname bump
* Thu Jan 30 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.3-4
– Fix baselineCPU EXPAND_FEATURES (bz #1049391)
* Mon Jan 27 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.3-3
– Rebuild for openwsman soname bump
* Mon Jan 20 2014 Richard W.M. Jones <rjones@redhat.com> – 1.1.3.3-2
– Backport increase default qemu monitor timeout from 3 to 30
seconds (bz #987088)
* Thu Jan 16 2014 Cole Robinson <crobinso@redhat.com> – 1.1.3.3-1
– Rebased to version 1.1.3.3
– Fix crash in virDBusAddWatch (bz #885445)
– Cleanup migration ports when migration is cancelled (bz #1018530)
– Fix virt-login-shell (bz #1054479)
– CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to
libvirtd crash (bz #1054206, bz #1048631)
– CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters (bz #1049136,
bz #1042252)
– CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL (bz
* Sat Dec 14 2013 Cole Robinson <crobinso@redhat.com> – 1.1.3.2-1
– Rebased to version 1.1.3.2
– Fix occasional libvirt-guests.service startup failure (bz #906009)
– Fix hotplugging USB device to qemu VM (bz #1016511)
– Fix return code of baselineCPU python API (bz #1033039)
– Don’t reload libvirt-guests when libvirt-client is updated (bz #962225)
– Fix infinite loop in libvirt_lxc (bz #1005570)
– Fix vdsm-tool segfault during vdsm startup (bz #1034312)
——————————————————————————–
References:

[ 1 ] Bug #1184431 – CVE-2015-0236 libvirt: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects
https://bugzilla.redhat.com/show_bug.cgi?id=1184431
[ 2 ] Bug #1176176 – CVE-2014-8136 libvirt: local denial of service in qemu/qemu_driver.c
https://bugzilla.redhat.com/show_bug.cgi?id=1176176
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update libvirt’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

 

AutorTomislav Protega
Cert idNCERT-REF-2015-02-0018-ADV
CveCVE-2014-8131 CVE-2015-0236 CVE-2014-8136
ID izvornikaFEDORA-2015-1892
Proizvodlibvirt
Izvorhttp://www.redhat.com
Top
More in Preporuke
Ranjivost programskog paketa bugzilla

Otkrivena je ranjivost u programskom paketu bugzilla za Fedoru. Ranjivost udaljenim autenticiranim korisnicima omogućuje izvršavanje proizvoljnih naredbi povišenjem privilegija za...

Close