MGASA-2014-0401
Dashboard / Vulnerabilities / MGASA-2014-0401
Summary: Updated libvirt packages fix security vulnerbilities
Details: Updated libvirt packages fix security vulnerabilities: An out-of-bounds read flaw was found in the way libvirt's qemuDomainGetBlockIoTune() function looked up the disk index in a non-persistent (live) disk configuration while a persistent disk configuration was being indexed. A remote attacker able to establish a read-only connection to libvirtd could use this flaw to crash libvirtd or, potentially, leak memory from the libvirtd process (CVE-2014-3633). A denial of service flaw was found in the way libvirt's virConnectListAllDomains() function computed the number of used domains. A remote attacker able to establish a read-only connection to libvirtd could use this flaw to make any domain operations within libvirt unresponsive (CVE-2014-3657).
References: https://advisories.mageia.org/MGASA-2014-0401.html, https://bugs.mageia.org/show_bug.cgi?id=14192, https://www.redhat.com/archives/libvir-list/2014-September/msg01164.html, https://rhn.redhat.com/errata/RHSA-2014-1352.html
Affected packages
Package
Name: libvirt
Purl: pkg:rpm/mageia/libvirt?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
