Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2015-0008

Опубликовано: 05 янв. 2015
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2015-0008: libvirt security and bug fix update (LOW)

[1.1.1-29.0.1.el7_0.4]

  • Replace docs/et.png in tarball with blank image

[1.1.1-29.el7_0.4]

  • qemu: blockcopy: Don't remove existing disk mirror info (rhbz#1149078)
  • qemu: copy: Accept 'format' parameter when copying to a non-existing img (rhbz#1149078)
  • qemu: reject rather than hang on blockcommit of active layer (rhbz#1150379)
  • CVE-2014-7823: dumpxml: security hole with migratable flag (CVE-2014-7823)
  • Fix crash when saving a domain with type none dac label (rhbz#1171124)

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

libvirt

1.1.1-29.0.1.el7_0.4

libvirt-client

1.1.1-29.0.1.el7_0.4

libvirt-daemon

1.1.1-29.0.1.el7_0.4

libvirt-daemon-config-network

1.1.1-29.0.1.el7_0.4

libvirt-daemon-config-nwfilter

1.1.1-29.0.1.el7_0.4

libvirt-daemon-driver-interface

1.1.1-29.0.1.el7_0.4

libvirt-daemon-driver-lxc

1.1.1-29.0.1.el7_0.4

libvirt-daemon-driver-network

1.1.1-29.0.1.el7_0.4

libvirt-daemon-driver-nodedev

1.1.1-29.0.1.el7_0.4

libvirt-daemon-driver-nwfilter

1.1.1-29.0.1.el7_0.4

libvirt-daemon-driver-qemu

1.1.1-29.0.1.el7_0.4

libvirt-daemon-driver-secret

1.1.1-29.0.1.el7_0.4

libvirt-daemon-driver-storage

1.1.1-29.0.1.el7_0.4

libvirt-daemon-kvm

1.1.1-29.0.1.el7_0.4

libvirt-daemon-lxc

1.1.1-29.0.1.el7_0.4

libvirt-devel

1.1.1-29.0.1.el7_0.4

libvirt-docs

1.1.1-29.0.1.el7_0.4

libvirt-lock-sanlock

1.1.1-29.0.1.el7_0.4

libvirt-login-shell

1.1.1-29.0.1.el7_0.4

libvirt-python

1.1.1-29.0.1.el7_0.4

Связанные CVE

Связанные уязвимости

ubuntu
почти 11 лет назад

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

redhat
почти 11 лет назад

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

nvd
почти 11 лет назад

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

debian
почти 11 лет назад

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote rea ...

github
больше 3 лет назад

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.