Mangelnde Rechteprüfung in libvirt
ID: | FEDORA-2016-65cc608ebe |
Distribution: | Fedora |
Plattformen: | Fedora 24 |
Datum: | Sa, 23. Juli 2016, 06:25 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5008 |
Applikationen: | libvirt |
Originalnachricht |
|
Name : libvirt Product : Fedora 24 Version : 1.3.3.2 Release : 1.fc24 URL : http://libvirt.org/ Summary : Library providing a simple virtualization API Description : Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support. -------------------------------------------------------------------------------- Update Information: * Rebased to version 1.3.3.2 * Fix xen default video device config (bz #1336629) * Don't reject duplicate disk serials (bz #1349895) * Fix LXC cgroup name mismatch (bz #1350139) * Fix managed save/restore with VM USB Keyboard (bz #1353222) * Missing dep on systemd-container (bz #1355784) * CVE-2016-5008: Setting empty VNC password allows access to unauthorized users (bz #1351516) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1351514 - CVE-2016-5008 libvirt: Setting empty VNC password allows access to unauthorized users https://bugzilla.redhat.com/show_bug.cgi?id=1351514 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libvirt' at the command line. For more information, refer to "Managing Software with yum", available at https://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://lists.fedoraproject.org/admin/lists/package-announce@lists.fedoraproject.org |