MGASA-2014-0243

Source
https://advisories.mageia.org/MGASA-2014-0243.html
Import Source
https://advisories.mageia.org/MGASA-2014-0243.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0243
Related
Published
2014-05-29T07:01:13Z
Modified
2014-05-29T07:00:43Z
Summary
Updated libvirt packages fix multiple vulnerabilities
Details

Updated libvirt packages fix security vulnerabilities:

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to paths under /proc//root and the virInitctlSetRunLevel function (CVE-2013-6456).

libvirt was patched to prevent expansion of entities when parsing XML files. This vulnerability allowed malicious users to read arbitrary files or cause a denial of service (CVE-2014-0179).

References
Credits

Affected packages

Mageia:3 / libvirt

Package

Name
libvirt
Purl
pkg:rpm/mageia/libvirt?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.2-8.5.mga3

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / libvirt

Package

Name
libvirt
Purl
pkg:rpm/mageia/libvirt?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.1-1.1.mga4

Ecosystem specific

{
    "section": "core"
}