Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian Jessie: DLA-1772-1 Moderate: Libvirt Information Disclosure

debian lts
Calendar Grey April 30, 2019
Dist Debian Esm H88
Debian LTS users can now access a libvirt patch that resolves possible info leakage and DoS vulnerabilities. Update immediately!
libvirt-domain.c in libvirt supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required

Summary

For Debian 8 "Jessie", this problem has been fixed in version
1.2.9-9+deb8u6.

We recommend that you upgrade your libvirt packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: libvirt
Version: 1.2.9-9+deb8u6
CVE ID: CVE-2016-10746

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here