libvirt-0.6.3-33.3.0.1.AXS3
エラータID: AXSA:2010-411:04
Release date:
Thursday, August 12, 2010 - 10:54
Subject:
libvirt-0.6.3-33.3.0.1.AXS3
Affected Channels:
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity:
High
Description:
Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes).
Security issues fixed with this release:
CVE-2010-2239
CVE-2010-2242
No information available at the time of writing, refer to the links below.
Fixed bugs
- Eliminate memory leak in xenUnifiedDomainInfoListFree
- Fix discrepancy between xm list and virsh list
- Set a stable & high MAC addr for guest TAP devices on host
Solution:
Update packages.
CVEs:
CVE-2010-2239
Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read arbitrary files on the host OS via unspecified vectors.
Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read arbitrary files on the host OS via unspecified vectors.
CVE-2010-2242
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
Additional Info:
N/A
Download:
SRPMS
- libvirt-0.6.3-33.3.0.1.AXS3.src.rpm
MD5: 0fec2eb7561011e12ce94562a0f86102
SHA-256: 73b1b0082dd3cc6058cab4985d507d2d40ab33ce07cc14df71c43c0587486f98
Size: 6.80 MB
Asianux Server 3 for x86
- libvirt-0.6.3-33.3.0.1.AXS3.i386.rpm
MD5: 2999c8328781f9df8c647c9e6a161d0d
SHA-256: 712dca97b9e6b527eeb95e022de175e3f67aa1cc81f9dfb931b3ad665bde73eb
Size: 1.97 MB - libvirt-devel-0.6.3-33.3.0.1.AXS3.i386.rpm
MD5: 41ca3e7f08a329cc83670b4c156b99a1
SHA-256: 06a9a70c967d05bb45ec4f2581a63125c748353a8304cd612f8d7f557f097aa7
Size: 254.61 kB - libvirt-python-0.6.3-33.3.0.1.AXS3.i386.rpm
MD5: 36ecc9fde24b5b6a268fd59cbecaf274
SHA-256: 24a420b6fbeab1ac3aa06015907fdd410324d45c653f7a5d466491c470555a2a
Size: 137.14 kB
Asianux Server 3 for x86_64
- libvirt-0.6.3-33.3.0.1.AXS3.x86_64.rpm
MD5: ed5dbe3b4630b82fa6822609cfb63bea
SHA-256: 39e3e8603fa02cd95bdc6547d648ccb83a4235434dadaf5cad8231d32f3f91ec
Size: 1.98 MB - libvirt-devel-0.6.3-33.3.0.1.AXS3.x86_64.rpm
MD5: c191d3fba283650e7af06bd243a1cbe9
SHA-256: a2869eb8af1bcd172d837cf22b95dd81276ad1cc4ec425a9360bc3c0b44636cf
Size: 254.56 kB - libvirt-python-0.6.3-33.3.0.1.AXS3.x86_64.rpm
MD5: a94483184e68e76207f6ed6d7d8ff108
SHA-256: 0a3a8383816494527458224b7a0204c7049d17d225c8b6e3b078d0c3ebe0ad2f
Size: 138.25 kB