Описание
ELSA-2013-1536: libguestfs security, bug fix, and enhancement update (MODERATE)
[1:1.20.11-2]
- Fix CVE-2013-4419: insecure temporary directory handling for guestfish's network socket resolves: rhbz#1019737
[1:1.20.11-1]
- Rebase to libguestfs 1.20.11. resolves: rhbz#958183
- Remove buildnet: builds now detect network automatically.
- The rhel-6.x branches containing the patches used in RHEL are now stored on a public git repository (https://github.com/libguestfs/libguestfs/branches).
- Compare spec file to Fedora 18 and fix where necessary.
- Backport new APIs part-get-gpt-type and part-set-gpt-type resolves: rhbz#965495
- Fix DoS (abort) due to a double free flaw when inspecting certain guest files / images (CVE-2013-2124) resolves: rhbz#968337
- libguestfs-devel should depend on an explicit version of libguestfs-tools-c, in order that the latest package is pulled in.
- Rebuild against Augeas >= 1.0.0-5 resolves: rhbz#971207
- Backport Windows inspection changes resolves: rhbz#971090
- Add back state test commands to guestfish resolves: rhbz#971664
- Work around problem with ntfsresize command in RHEL 6 resolves: rhbz#971326
- Fix txz-out API resolves: rhbz#972413
- Move virt-sysprep to the libguestfs-tools-c package since it's no longer a shell script resolves: rhbz#975572
- Fix hostname inspection because of faulty Augeas path expression resolves: rhbz#975377
- Calculate appliance root correctly when iface drives are added resolves: rhbz#975760
- Add notes about resizing Windows disk images to virt-resize documentation resolves: rhbz#975753
- Remove dependency on lsscsi, not available in 6Client resolves: rhbz#973425
- Fix yum cache copy so it works if there are multiple repos resolves: rhbz#980502
- Fix hivex-commit API to fail with relative paths resolves: rhbz#980372
- Better documentation for filesystem-available API resolves: rhbz#980358
- Fix double free when kernel link fails during launch resolves: rhbz#983690
- Fix virt-sysprep --firstboot option resolves: rhbz#988863
- Fix cap-get-file so it returns empty string instead of error on no cap resolves: rhbz#989352
- Better documentation for acl-set-file resolves: rhbz#985269
- Fix bogus waitpid error when using guestfish --remote resolves: rhbz#996825
- Disable 9p support resolves: rhbz#997884
- Document that guestfish --remote doesn't work with certain other arguments resolves: rhbz#996039
- Enable kvmclock in the appliance to reduce clock instability resolves: rhbz#998108
- Fix 'sh' command before mount causes daemon to segfault resolves: rhbz#1000122
- Various fixes to tar-out 'excludes' (RHBZ#1001875)
- Document use of glob + rsync-out (RHBZ#1001876)
- Document mke2fs blockscount (RHBZ#1002032)
Обновленные пакеты
Oracle Linux 6
Oracle Linux x86_64
libguestfs
1.20.11-2.el6
libguestfs-devel
1.20.11-2.el6
libguestfs-java
1.20.11-2.el6
libguestfs-java-devel
1.20.11-2.el6
libguestfs-javadoc
1.20.11-2.el6
libguestfs-tools
1.20.11-2.el6
libguestfs-tools-c
1.20.11-2.el6
ocaml-libguestfs
1.20.11-2.el6
ocaml-libguestfs-devel
1.20.11-2.el6
perl-Sys-Guestfs
1.20.11-2.el6
python-libguestfs
1.20.11-2.el6
ruby-libguestfs
1.20.11-2.el6
Связанные CVE
Связанные уязвимости
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when ...
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.