Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE Linux Enterprise 15-SP1: Important Security Update for libvirt Threat

suse
Calendar Grey June 21, 2019
Dist Suse Esm H88
This release tackles critical vulnerabilities in OpenStack, enhancing overall system protection and application reliability.
An update that fixes four vulnerabilities is now available

Summary

This update for libvirt fixes the following issues: Security issues fixed: - CVE-2019-10161: Fixed virDomainSaveImageGetXMLDesc API which could accept a path parameter pointing anywhere on the system and potentially leading to execution of a malicious file with root privileges by libvirtd (bsc#1138301). - CVE-2019-10166: Fixed an issue with virDomainManagedSaveDefineXML which could have been used to alter the domain's config used for managedsave or execute arbitrary emulator binaries (bsc#1138302). - CVE-2019-10167: Fixed an issue with virConnectGetDomainCapabilities API which could have been used to execute arbitrary emulators (bsc#1138303). - CVE-2019-10168: Fixed an issue with virConnect*HypervisorCPU API which could have been used to execute arbitrary emulators (bsc#1138305).

References

#1138301 #1138302 #1138303 #1138305

Cross- CVE-2019-10161 CVE-2019-10166 CVE-2019-10167

CVE-2019-10168

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP1

SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2019-10161.html

https://www.suse.com/security/cve/CVE-2019-10166.html

https://www.suse.com/security/cve/CVE-2019-10167.html

https://www.suse.com/security/cve/CVE-2019-10168.html

https://bugzilla.suse.com/1138301

https://bugzilla.suse.com/1138302

https://bugzilla.suse.com/1138303

https://bugzilla.suse.com/1138305

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:1643-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here