Описание
Security update for libvirt
This update for libvirt fixes the following issues:
Security issue:
- CVE-2015-5313: directory directory traversal privilege escalation vulnerability. (bsc#953110)
Bugs fixed:
- bsc#960305: xenxs: support parsing and formatting vif bandwidth
- bsc#961173: xen: use correct domctl version in domaininfolist union
- bsc#959094: xen: Disable building xen-inotify subdriver. It is unmaintained and contains bugs that can cause client connection failures.
- bsc#948686: qemu: Use PAUSED state for domains that are starting up
- bsc#948516: Fix profile_status to distringuish between errors and unconfined domains.
Список пакетов
SUSE Linux Enterprise Desktop 11 SP4
libvirt-1.2.5-12.3
libvirt-client-1.2.5-12.3
libvirt-client-32bit-1.2.5-12.3
libvirt-doc-1.2.5-12.3
SUSE Linux Enterprise Server 11 SP4
libvirt-1.2.5-12.3
libvirt-client-1.2.5-12.3
libvirt-client-32bit-1.2.5-12.3
libvirt-doc-1.2.5-12.3
libvirt-lock-sanlock-1.2.5-12.3
SUSE Linux Enterprise Server for SAP Applications 11 SP4
libvirt-1.2.5-12.3
libvirt-client-1.2.5-12.3
libvirt-client-32bit-1.2.5-12.3
libvirt-doc-1.2.5-12.3
libvirt-lock-sanlock-1.2.5-12.3
SUSE Linux Enterprise Software Development Kit 11 SP4
libvirt-devel-1.2.5-12.3
libvirt-devel-32bit-1.2.5-12.3
Ссылки
- Link for SUSE-SU-2016:0931-1
- E-Mail link for SUSE-SU-2016:0931-1
- SUSE Security Ratings
- SUSE Bug 948516
- SUSE Bug 948686
- SUSE Bug 953110
- SUSE Bug 959094
- SUSE Bug 960305
- SUSE Bug 961173
- SUSE CVE CVE-2015-5313 page
Описание
Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write to arbitrary files via a .. (dot dot) in a volume name.
Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP4:libvirt-1.2.5-12.3
SUSE Linux Enterprise Desktop 11 SP4:libvirt-client-1.2.5-12.3
SUSE Linux Enterprise Desktop 11 SP4:libvirt-client-32bit-1.2.5-12.3
SUSE Linux Enterprise Desktop 11 SP4:libvirt-doc-1.2.5-12.3
Ссылки
- CVE-2015-5313
- SUSE Bug 953110