Login
Newsletter
Werbung

Sicherheit: Fehlerhafte Zugriffsrechte in libvirt
Aktuelle Meldungen Distributionen
Name: Fehlerhafte Zugriffsrechte in libvirt
ID: FEDORA-2014-2864
Distribution: Fedora
Plattformen: Fedora 20
Datum: Sa, 1. März 2014, 21:10
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6456
Applikationen: libvirt

Originalnachricht

Name        : libvirt
Product : Fedora 20
Version : 1.1.3.4
Release : 1.fc20
URL : http://libvirt.org/
Summary : Library providing a simple virtualization API
Description :
Libvirt is a C toolkit to interact with the virtualization capabilities
of recent versions of Linux (and other OSes). The main package includes
the libvirtd server exporting the virtualization support.

-------------------------------------------------------------------------------
-
Update Information:

* Rebased to version 1.1.3.4
* Fix domain events when ACLs are used (bz #1058839)
* CVE-2013-6456: unsafe usage of paths under /proc//root (bz #1048628, bz
#1048627)
* Fix baselineCPU EXPAND_FEATURES (bz #1049391)
-------------------------------------------------------------------------------
-
ChangeLog:

* Tue Feb 18 2014 Cole Robinson <crobinso@redhat.com> - 1.1.3.4-1
- Rebased to version 1.1.3.4
- Fix domain events when ACLs are used (bz #1058839)
- CVE-2013-6456: unsafe usage of paths under /proc//root (bz #1048628, bz
* Sat Feb 1 2014 Cole Robinson <crobinso@redhat.com> - 1.1.3.3-5
- Rebuild again for openwsman soname bump
* Thu Jan 30 2014 Cole Robinson <crobinso@redhat.com> - 1.1.3.3-4
- Fix baselineCPU EXPAND_FEATURES (bz #1049391)
* Mon Jan 27 2014 Cole Robinson <crobinso@redhat.com> - 1.1.3.3-3
- Rebuild for openwsman soname bump
* Mon Jan 20 2014 Richard W.M. Jones <rjones@redhat.com> - 1.1.3.3-2
- Backport increase default qemu monitor timeout from 3 to 30
seconds (bz #987088)
* Thu Jan 16 2014 Cole Robinson <crobinso@redhat.com> - 1.1.3.3-1
- Rebased to version 1.1.3.3
- Fix crash in virDBusAddWatch (bz #885445)
- Cleanup migration ports when migration is cancelled (bz #1018530)
- Fix virt-login-shell (bz #1054479)
- CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to
libvirtd crash (bz #1054206, bz #1048631)
- CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters (bz #1049136,
bz #1042252)
- CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL (bz
* Sat Dec 14 2013 Cole Robinson <crobinso@redhat.com> - 1.1.3.2-1
- Rebased to version 1.1.3.2
- Fix occasional libvirt-guests.service startup failure (bz #906009)
- Fix hotplugging USB device to qemu VM (bz #1016511)
- Fix return code of baselineCPU python API (bz #1033039)
- Don't reload libvirt-guests when libvirt-client is updated (bz #962225)
- Fix infinite loop in libvirt_lxc (bz #1005570)
- Fix vdsm-tool segfault during vdsm startup (bz #1034312)
-------------------------------------------------------------------------------
-
References:

[ 1 ] Bug #1048627 - CVE-2013-6456 libvirt: unsafe usage of paths under
/proc/$PID/root
https://bugzilla.redhat.com/show_bug.cgi?id=1048627
-------------------------------------------------------------------------------
-

This update can be installed with the "yum" update program. Use
su -c 'yum update libvirt' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
-------------------------------------------------------------------------------
-
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung