Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2013-1536

Опубликовано: 26 нояб. 2013
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2013-1536: libguestfs security, bug fix, and enhancement update (MODERATE)

[1:1.20.11-2]

  • Fix CVE-2013-4419: insecure temporary directory handling for guestfish's network socket resolves: rhbz#1019737

[1:1.20.11-1]

  • Rebase to libguestfs 1.20.11. resolves: rhbz#958183
  • Remove buildnet: builds now detect network automatically.
  • The rhel-6.x branches containing the patches used in RHEL are now stored on a public git repository (https://github.com/libguestfs/libguestfs/branches).
  • Compare spec file to Fedora 18 and fix where necessary.
  • Backport new APIs part-get-gpt-type and part-set-gpt-type resolves: rhbz#965495
  • Fix DoS (abort) due to a double free flaw when inspecting certain guest files / images (CVE-2013-2124) resolves: rhbz#968337
  • libguestfs-devel should depend on an explicit version of libguestfs-tools-c, in order that the latest package is pulled in.
  • Rebuild against Augeas >= 1.0.0-5 resolves: rhbz#971207
  • Backport Windows inspection changes resolves: rhbz#971090
  • Add back state test commands to guestfish resolves: rhbz#971664
  • Work around problem with ntfsresize command in RHEL 6 resolves: rhbz#971326
  • Fix txz-out API resolves: rhbz#972413
  • Move virt-sysprep to the libguestfs-tools-c package since it's no longer a shell script resolves: rhbz#975572
  • Fix hostname inspection because of faulty Augeas path expression resolves: rhbz#975377
  • Calculate appliance root correctly when iface drives are added resolves: rhbz#975760
  • Add notes about resizing Windows disk images to virt-resize documentation resolves: rhbz#975753
  • Remove dependency on lsscsi, not available in 6Client resolves: rhbz#973425
  • Fix yum cache copy so it works if there are multiple repos resolves: rhbz#980502
  • Fix hivex-commit API to fail with relative paths resolves: rhbz#980372
  • Better documentation for filesystem-available API resolves: rhbz#980358
  • Fix double free when kernel link fails during launch resolves: rhbz#983690
  • Fix virt-sysprep --firstboot option resolves: rhbz#988863
  • Fix cap-get-file so it returns empty string instead of error on no cap resolves: rhbz#989352
  • Better documentation for acl-set-file resolves: rhbz#985269
  • Fix bogus waitpid error when using guestfish --remote resolves: rhbz#996825
  • Disable 9p support resolves: rhbz#997884
  • Document that guestfish --remote doesn't work with certain other arguments resolves: rhbz#996039
  • Enable kvmclock in the appliance to reduce clock instability resolves: rhbz#998108
  • Fix 'sh' command before mount causes daemon to segfault resolves: rhbz#1000122
  • Various fixes to tar-out 'excludes' (RHBZ#1001875)
  • Document use of glob + rsync-out (RHBZ#1001876)
  • Document mke2fs blockscount (RHBZ#1002032)

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

libguestfs

1.20.11-2.el6

libguestfs-devel

1.20.11-2.el6

libguestfs-java

1.20.11-2.el6

libguestfs-java-devel

1.20.11-2.el6

libguestfs-javadoc

1.20.11-2.el6

libguestfs-tools

1.20.11-2.el6

libguestfs-tools-c

1.20.11-2.el6

ocaml-libguestfs

1.20.11-2.el6

ocaml-libguestfs-devel

1.20.11-2.el6

perl-Sys-Guestfs

1.20.11-2.el6

python-libguestfs

1.20.11-2.el6

ruby-libguestfs

1.20.11-2.el6

Связанные CVE

Связанные уязвимости

ubuntu
почти 12 лет назад

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.

redhat
почти 12 лет назад

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.

nvd
почти 12 лет назад

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.

debian
почти 12 лет назад

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when ...

github
больше 3 лет назад

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.