Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Ubuntu 13.10: 2093-1 Critical: Libvirt Denial of Service Issues

ubuntu
Calendar Grey January 30, 2014
Scroller Ubuntu
Revise your framework to mitigate various vulnerabilities in libvirt for Ubuntu, particularly concerning DoS threats impacting vital versions.
Several security issues were fixed in libvirt.

Summary

Several security issues were fixed in libvirt.

Software Description:

- libvirt: Libvirt virtualization toolkit

Details:

Martin Kletzander discovered that libvirt incorrectly handled reading

memory tunables from LXC guests. A local user could possibly use this flaw

to cause libvirtd to crash, resulting in a denial of service. This issue

only affected Ubuntu 13.10. (CVE-2013-6436)

Dario Faggioli discovered that libvirt incorrectly handled the libxl

driver. A local user could possibly use this flaw to cause libvirtd to

crash, resulting in a denial of service, or possibly execute arbitrary

code. This issue only affected Ubuntu 13.10. (CVE-2013-6457)

It was discovered that libvirt contained multiple race conditions in block

device handling. A remote read-only user could use this flaw to cause

libvirtd to crash, resulting in a denial of service. (CVE-2013-6458)

Eric Blake discovered that libvirt incorrectly handled certain ACLs. An

attacker could use this fla...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  libvirt-bin                     1.1.1-0ubuntu8.5
  libvirt0                        1.1.1-0ubuntu8.5

Ubuntu 12.10:
  libvirt-bin                     0.9.13-0ubuntu12.6
  libvirt0                        0.9.13-0ubuntu12.6

Ubuntu 12.04 LTS:
  libvirt-bin                     0.9.8-2ubuntu17.17
  libvirt0                        0.9.8-2ubuntu17.17

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2093-1

CVE-2013-6436, CVE-2013-6457, CVE-2013-6458, CVE-2014-0028,

CVE-2014-1447

Severity
critical
Lowest
Low
Medium
High
Critical

January 30, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.