MGASA-2015-0046
Dashboard / Vulnerabilities / MGASA-2015-0046
Summary: Updated libvirt packages fix CVE-2015-0236
Details: Updated libvirt packages fix security vulnerability: The XML getters for save images and snapshots objects don't check ACLs for the VIR_DOMAIN_XML_SECURE flag and might possibly dump security sensitive information. A remote attacker able to establish a connection to libvirtd could use this flaw to cause leak certain limited information from the domain xml file (CVE-2015-0236).
References: https://advisories.mageia.org/MGASA-2015-0046.html, https://bugs.mageia.org/show_bug.cgi?id=15141, https://bugzilla.redhat.com/show_bug.cgi?id=1184431, http://security.libvirt.org/2015/0001.html
Affected packages
Package
Name: libvirt
Purl: pkg:rpm/mageia/libvirt?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
