[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2013-0199 -- Oracle libvirt

ID: oval:org.secpod.oval:def:1500081Date: (C)2013-03-20   (M)2023-02-20
Class: PATCHFamily: unix




Updated libvirt packages that fix one security issue are now available forRed Hat Enterprise Linux 6.The Red Hat Security Response Team has rated this update as havingimportant security impact. A Common Vulnerability Scoring System base score, which gives a detailed severity rating, is available from theCVE link in the References section. The libvirt library is a C API for managing and interacting with thevirtualization capabilities of Linux and other operating systems. Inaddition, libvirt provides tools for remote management of virtualizedsystems.A flaw was found in the way libvirtd handled connection cleanup under certain error conditions. A remoteattacker able to establish a read-only connection to libvirtd could usethis flaw to crash libvirtd or, potentially, execute arbitrary code withthe privileges of the root user. This issue was discovered by Tingting Zheng of Red Hat.All users of libvirt are advised to upgrade to these updated packages,which contain a backported patch to correct this issue. After installingthe updated packages, libvirtd will be restarted automatically.

Platform:
Oracle Linux 6
Product:
libvirt
Reference:
ELSA-2013-0199
CVE-2013-0170
CVE    1
CVE-2013-0170
CPE    11
cpe:/a:redhat:libvirt:0.10.2.2
cpe:/a:redhat:libvirt:0.10.2
cpe:/a:redhat:libvirt:0.10.2.1
cpe:/a:redhat:libvirt:1.0.1
...

© SecPod Technologies