LWN.net Logo

Mageia alert MGASA-2013-0235 (qemu)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2013-0235: Updated qemu package fixes CVE-2013-2231
Date:  Fri, 26 Jul 2013 13:54:57 +0200
Message-ID:  <20130726115457.857AA4308F@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2013-0235 - Updated qemu package fixes CVE-2013-2231 Publication date: 26 Jul 2013 URL: http://advisories.mageia.org/MGASA-2013-0235.html Type: security Affected Mageia releases: 3 CVE: CVE-2013-2231 Description: Updated qemu packages fix security vulnerability: An unquoted search path flaw was found in the way the QEMU Guest Agent service installation was performed on Windows. Depending on the permissions of the directories in the unquoted search path, a local, unprivileged user could use this flaw to have a binary of their choosing executed with SYSTEM privileges (CVE-2013-2231). References: - https://rhn.redhat.com/errata/RHSA-2013-1100.html - https://bugs.mageia.org/show_bug.cgi?id=10829 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2231 SRPMS: - 3/core/qemu-1.2.0-8.2.mga3


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds