Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-4469-1 Moderate: libvirt API Abuse and Arbitrary File Access

debian
Calendar Grey June 22, 2019
Debian Logo
The Debian Security Advisory DSA-4469-1 reveals vulnerabilities in libvirt that could permit unauthorized command execution and file exploitation.
Two vulnerabilities were discovered in Libvirt, a virtualisation abstraction library, allowing an API client with read-only permissions to execute arbitrary commands via the virCon...

Summary

Additionally the libvirt's cpu map was updated to make addressing
CVE-2018-3639, CVE-2017-5753, CVE-2017-5715, CVE-2018-12126,
CVE-2018-12127, CVE-2018-12130 and CVE-2019-11091 easier by supporting
the md-clear, ssbd, spec-ctrl and ibpb CPU features when picking CPU
models without having to fall back to host-passthrough.

For the stable distribution (stretch), these problems have been fixed in
version 3.0.0-4+deb9u4.

We recommend that you upgrade your libvirt packages.

For the detailed security status of libvirt please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/libvirt

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: libvirt
CVE ID: CVE-2019-10161 CVE-2019-10167

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here