openSUSE Security Update: libvirt to fix use-after-free in virNetMessageFree()
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2013:0274-1
Rating:             important
References:         #772586 #773621 #773626 #780432 #800976 
Cross-References:   CVE-2012-4423 CVE-2013-0170
Affected Products:
                    openSUSE 12.1
______________________________________________________________________________

   An update that solves two vulnerabilities and has three
   fixes is now available.

Description:


   libvirt was updated to fix some bugs and security issues:

   Security issues fixed:
   - Fix crash on error paths of message dispatching,
   CVE-2013-0170 bnc#800976
   - security: Fix libvirtd crash possibility CVE-2012-4423
   bnc#780432

   Also bugs were fixed:
   - qemu: Fix probing for guest capabilities bnc#772586
   - xen-xm: Generate UUID if not specified bnc#773626
   - xenParseXM: don't dereference NULL pointer when script is
   empty bnc#773621


Patch Instructions:

   To install this openSUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - openSUSE 12.1:

      zypper in -t patch openSUSE-2013-105

   To bring your system up-to-date, use "zypper patch".


Package List:

   - openSUSE 12.1 (i586 x86_64):

      libvirt-0.9.6-3.13.1
      libvirt-client-0.9.6-3.13.1
      libvirt-client-debuginfo-0.9.6-3.13.1
      libvirt-debuginfo-0.9.6-3.13.1
      libvirt-debugsource-0.9.6-3.13.1
      libvirt-devel-0.9.6-3.13.1
      libvirt-doc-0.9.6-3.13.1
      libvirt-python-0.9.6-3.13.1
      libvirt-python-debuginfo-0.9.6-3.13.1

   - openSUSE 12.1 (x86_64):

      libvirt-client-32bit-0.9.6-3.13.1
      libvirt-client-debuginfo-32bit-0.9.6-3.13.1
      libvirt-devel-32bit-0.9.6-3.13.1

   - openSUSE 12.1 (ia64):

      libvirt-client-debuginfo-x86-0.9.6-3.13.1
      libvirt-client-x86-0.9.6-3.13.1


References:

   https://www.suse.com/security/cve/CVE-2012-4423.html
   https://www.suse.com/security/cve/CVE-2013-0170.html
   https://bugzilla.novell.com/772586
   https://bugzilla.novell.com/773621
   https://bugzilla.novell.com/773626
   https://bugzilla.novell.com/780432
   https://bugzilla.novell.com/800976

openSUSE: 2013:0274-1: important: libvirt

February 12, 2013
An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now...

Description

libvirt was updated to fix some bugs and security issues: Security issues fixed: - Fix crash on error paths of message dispatching, CVE-2013-0170 bnc#800976 - security: Fix libvirtd crash possibility CVE-2012-4423 bnc#780432 Also bugs were fixed: - qemu: Fix probing for guest capabilities bnc#772586 - xen-xm: Generate UUID if not specified bnc#773626 - xenParseXM: don't dereference NULL pointer when script is empty bnc#773621

 

Patch

Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 12.1: zypper in -t patch openSUSE-2013-105 To bring your system up-to-date, use "zypper patch".


Package List

- openSUSE 12.1 (i586 x86_64): libvirt-0.9.6-3.13.1 libvirt-client-0.9.6-3.13.1 libvirt-client-debuginfo-0.9.6-3.13.1 libvirt-debuginfo-0.9.6-3.13.1 libvirt-debugsource-0.9.6-3.13.1 libvirt-devel-0.9.6-3.13.1 libvirt-doc-0.9.6-3.13.1 libvirt-python-0.9.6-3.13.1 libvirt-python-debuginfo-0.9.6-3.13.1 - openSUSE 12.1 (x86_64): libvirt-client-32bit-0.9.6-3.13.1 libvirt-client-debuginfo-32bit-0.9.6-3.13.1 libvirt-devel-32bit-0.9.6-3.13.1 - openSUSE 12.1 (ia64): libvirt-client-debuginfo-x86-0.9.6-3.13.1 libvirt-client-x86-0.9.6-3.13.1


References

https://www.suse.com/security/cve/CVE-2012-4423.html https://www.suse.com/security/cve/CVE-2013-0170.html https://bugzilla.novell.com/772586 https://bugzilla.novell.com/773621 https://bugzilla.novell.com/773626 https://bugzilla.novell.com/780432 https://bugzilla.novell.com/800976


Severity
Announcement ID: openSUSE-SU-2013:0274-1
Rating: important
Affected Products: openSUSE 12.1

Related News