=========================================================================Ubuntu Security Notice USN-4452-1
August 04, 2020

libvirt vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

libvirt could be made to run programs as an administrator.

Software Description:
- libvirt: Libvirt virtualization toolkit

Details:

Trent Shea discovered that the libvirt package set incorrect permissions on
the UNIX domain socket. A local attacker could use this issue to access
libvirt and escalate privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  libvirt-daemon                  6.0.0-0ubuntu8.3
  libvirt-daemon-system           6.0.0-0ubuntu8.3
  libvirt0                        6.0.0-0ubuntu8.3

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4452-1
  CVE-2020-15708

Package Information:
  https://launchpad.net/ubuntu/+source/libvirt/6.0.0-0ubuntu8.3

Ubuntu 4452-1: libvirt vulnerability

August 4, 2020
libvirt could be made to run programs as an administrator.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libvirt-daemon 6.0.0-0ubuntu8.3 libvirt-daemon-system 6.0.0-0ubuntu8.3 libvirt0 6.0.0-0ubuntu8.3 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4452-1

CVE-2020-15708

Severity
August 04, 2020

Package Information

https://launchpad.net/ubuntu/+source/libvirt/6.0.0-0ubuntu8.3

Related News