Mageia alert MGASA-2013-0294 (libvirt)
From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2013-0294: Updated libvirt package fixes security vulnerabilities | |
Date: | Sat, 5 Oct 2013 19:55:48 +0200 | |
Message-ID: | <20131005175549.0858A5B290@valstar.mageia.org> |
MGASA-2013-0294 - Updated libvirt package fixes security vulnerabilities Publication date: 05 Oct 2013 URL: http://advisories.mageia.org/MGASA-2013-0294.html Type: security Affected Mageia releases: 2, 3 CVE: CVE-2013-4296, CVE-2013-4311, CVE-2013-5651 Description: It was discovered that libvirt incorrectly handled certain memory stats requests. A remote attacker could use this issue to cause libvirt to crash, resulting in a denial of service (CVE-2013-4296). It was discovered that libvirt incorrectly handled certain bitmap operations. A remote attacker could use this issue to cause libvirt to crash, resulting in a denial of service (CVE-2013-5651). Additionally, an update for a PolicyKit security issue required libvirt to be updated to use a different API that is not affected by this security issue (CVE-2013-4311). References: - https://bugs.mageia.org/show_bug.cgi?id=11274 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4296 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4311 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5651 SRPMS: - 3/core/libvirt-1.0.2-8.4.mga3 - 2/core/libvirt-0.9.12-1.mga2