Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:0931-1

Опубликовано: 01 апр. 2016
Источник: suse-cvrf

Описание

Security update for libvirt

This update for libvirt fixes the following issues:

Security issue:

  • CVE-2015-5313: directory directory traversal privilege escalation vulnerability. (bsc#953110)

Bugs fixed:

  • bsc#960305: xenxs: support parsing and formatting vif bandwidth
  • bsc#961173: xen: use correct domctl version in domaininfolist union
  • bsc#959094: xen: Disable building xen-inotify subdriver. It is unmaintained and contains bugs that can cause client connection failures.
  • bsc#948686: qemu: Use PAUSED state for domains that are starting up
  • bsc#948516: Fix profile_status to distringuish between errors and unconfined domains.

Список пакетов

SUSE Linux Enterprise Desktop 11 SP4
libvirt-1.2.5-12.3
libvirt-client-1.2.5-12.3
libvirt-client-32bit-1.2.5-12.3
libvirt-doc-1.2.5-12.3
SUSE Linux Enterprise Server 11 SP4
libvirt-1.2.5-12.3
libvirt-client-1.2.5-12.3
libvirt-client-32bit-1.2.5-12.3
libvirt-doc-1.2.5-12.3
libvirt-lock-sanlock-1.2.5-12.3
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libvirt-1.2.5-12.3
libvirt-client-1.2.5-12.3
libvirt-client-32bit-1.2.5-12.3
libvirt-doc-1.2.5-12.3
libvirt-lock-sanlock-1.2.5-12.3
SUSE Linux Enterprise Software Development Kit 11 SP4
libvirt-devel-1.2.5-12.3
libvirt-devel-32bit-1.2.5-12.3

Описание

Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write to arbitrary files via a .. (dot dot) in a volume name.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP4:libvirt-1.2.5-12.3
SUSE Linux Enterprise Desktop 11 SP4:libvirt-client-1.2.5-12.3
SUSE Linux Enterprise Desktop 11 SP4:libvirt-client-32bit-1.2.5-12.3
SUSE Linux Enterprise Desktop 11 SP4:libvirt-doc-1.2.5-12.3

Ссылки