Debian LTS: DLA-1832-1: libvirt security update
Summary
* CVE-2019-10167: Prevent an arbitrary code execution vulnerability
via the API where a user-specified binary used to probe the
domain's capabilities. read-only clients could specify an
arbitrary path for this argument, causing libvirtd to execute a
crafted executable with its own privileges.
For Debian 8 "Jessie", these issues have been fixed in libvirt
version 1.2.9-9+deb8u7.
We recommend that you upgrade your libvirt packages.
Regards,
- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-