[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4003-1 libvirt -- libvirt

ID: oval:org.secpod.oval:def:603133Date: (C)2017-11-09   (M)2024-01-29
Class: PATCHFamily: unix




Daniel P. Berrange reported that Libvirt, a virtualisation abstraction library, does not properly handle the default_tls_x509_verify parameters in qemu.conf when setting up TLS clients and servers in QEMU, resulting in TLS clients for character devices and disk devices having verification turned off and ignoring any errors while validating the server certificate. More informations in https://security.libvirt.org/2017/0002.html .

Platform:
Debian 9.x
Product:
libvirt0
libvirt-dev
libnss-libvirt
libvirt-sanlock
libvirt-daemon
libvirt-clients
libvirt-doc
Reference:
DSA-4003-1
CVE-2017-1000256
CVE    1
CVE-2017-1000256
CPE    4
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:9.x
cpe:/a:redhat:libvirt
cpe:/a:redhat:libvirt:0
...

© SecPod Technologies