libvirt-0.9.10-21.5.0.1.AXS4
エラータID: AXSA:2012-975:04
Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.
Security issues fixed with this release:
• CVE-2012-4423
The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.
• CVE-2012-3445
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
Fixed bugs:
• The augeas libvirt was unable to parse the libvirt.conf file if it contained the host_uuid option; this has been fixed.
• Fixed the disk hot-plug functions.
• Fixed the rebase operation; cgroups for the backing files are now relabelled and configured so that, when a virtual machine with an image chain using block device is started, the block rebase works as expected instead of failing on the blockJobAbort() function.
• Previously, when migrating a guest between 2 machines while the tunnelled migration could cause the libvirt daemon to lock up unexpectedly; this has been fixed.
• Depending on the locale in used, libvirt could issue incorrect commands to the hypervisor. This has been fixed.
Update packages.
The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
N/A
SRPMS
- libvirt-0.9.10-21.5.0.1.AXS4.src.rpm
MD5: 8dd95218bee7fa76ce0e4d7601112afb
SHA-256: ed65d6d1ed21b528d41e9ba0c22ee72f3538797dd6034f4048ce1f3db35bbca6
Size: 18.80 MB
Asianux Server 4 for x86
- libvirt-0.9.10-21.5.0.1.AXS4.i686.rpm
MD5: 7888bbdfaf50cfef16bccab3c608e401
SHA-256: 0e6a6bbe766135bae6f8c3be2fb684b135e568c08407f85b63d7997eb9f1a4a4
Size: 1.66 MB - libvirt-client-0.9.10-21.5.0.1.AXS4.i686.rpm
MD5: 18f7068926a2d7da4479a48c90021b71
SHA-256: 01e91a1174cf08a2ddee0408cb48a07addcdba258663785eaad530431d8cc964
Size: 3.21 MB - libvirt-devel-0.9.10-21.5.0.1.AXS4.i686.rpm
MD5: 0de1269cdeac69fa7ae684036a24da7d
SHA-256: d6ede58f1670ef544a4da268c0610fdfd9808e9c971d809f1f8d10d4f426af9e
Size: 274.90 kB - libvirt-python-0.9.10-21.5.0.1.AXS4.i686.rpm
MD5: a9a1ff79f3292f9f3f87a06fdce3c960
SHA-256: 5aa8f1f730d226cb267af8238bd4e24e179d8a0aa1aa9aaa01ae0ff14817b5b9
Size: 394.38 kB
Asianux Server 4 for x86_64
- libvirt-0.9.10-21.5.0.1.AXS4.x86_64.rpm
MD5: 652164b1dc43f36bd084928f8426b21f
SHA-256: 7e15dfa8962ac17b71049942819d1d6c3d2c07cfca25efc2cb0121c17654489a
Size: 1.89 MB - libvirt-client-0.9.10-21.5.0.1.AXS4.x86_64.rpm
MD5: ce46583adff80adb1185d7483f9f6412
SHA-256: cf5363441ab8066da2bb2378c905f87d1b7579733c96d27714b4c4409fd6667d
Size: 3.22 MB - libvirt-devel-0.9.10-21.5.0.1.AXS4.x86_64.rpm
MD5: 256f9fb8ee12bf4f46d7e63875871911
SHA-256: 38c295878e1e63714e0eac19a2b8e017cf7b0306a54144195c1e59763b0ef987
Size: 274.51 kB - libvirt-python-0.9.10-21.5.0.1.AXS4.x86_64.rpm
MD5: 2c0f4a64d45f1796cd068b78eed952b8
SHA-256: 39a42bfb7aeb00365c8e9faa4f6a3b742dcf3c1dad265a177cfcb4563e4bb373
Size: 394.61 kB - libvirt-client-0.9.10-21.5.0.1.AXS4.i686.rpm
MD5: 18f7068926a2d7da4479a48c90021b71
SHA-256: 01e91a1174cf08a2ddee0408cb48a07addcdba258663785eaad530431d8cc964
Size: 3.21 MB - libvirt-devel-0.9.10-21.5.0.1.AXS4.i686.rpm
MD5: 0de1269cdeac69fa7ae684036a24da7d
SHA-256: d6ede58f1670ef544a4da268c0610fdfd9808e9c971d809f1f8d10d4f426af9e
Size: 274.90 kB