| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2013-0166: Updated libvirt packages fix
security vulnerability |
| Date: |
| Thu, 6 Jun 2013 21:23:53 +0200 |
| Message-ID: |
| <20130606192353.480AA4B5E0@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2013-0166 - Updated libvirt packages fix security vulnerability
Publication date: 06 Jun 2013
Type: security
Affected Mageia releases: 3
CVE: CVE-2013-1962
Description:
It was found that libvirtd leaked file descriptors when listing all volumes
for a particular pool. A remote attacker able to establish a read-only
connection to libvirtd could use this flaw to cause libvirtd to consume all
available file descriptors, preventing other users from using libvirtd
services (such as starting a new guest) until libvirtd is restarted
(CVE-2013-1962).
References:
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1962
- https://rhn.redhat.com/errata/RHSA-2013-0831.html
- https://bugs.mageia.org/show_bug.cgi?id=10345
SRPMS:
- 3/core/libvirt-1.0.2-7.1.mga3
(
Log in to post comments)