SUSE Security Update: Security update for libvirt
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:0320-1
Rating:             important
References:         #782311 #800976 
Cross-References:   CVE-2013-0170
Affected Products:
                    SUSE Linux Enterprise Software Development Kit 11 SP2
                    SUSE Linux Enterprise Server 11 SP2
                    SUSE Linux Enterprise Desktop 11 SP2
______________________________________________________________________________

   An update that solves one vulnerability and has one errata
   is now available.

Description:


   libvirt was updated to fix the following security issue:

   * A flaw was found in the way message freeing on
   connection cleanup was handled under certain error
   conditions. A remote user able to issue commands to libvirt
   daemon could use this flaw to crash libvirtd or,
   potentially, escalate their privilages to that of libvirtd
   process. (CVE-2013-0170)

   Also following bug has been fixed:

   * Add managedSave functions to legacy xen driver
   bnc#782311

   Security Issue reference:

   * CVE-2013-0170
   

Indications:

   Everyone should install this update.

Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Software Development Kit 11 SP2:

      zypper in -t patch sdksp2-libvirt-7310

   - SUSE Linux Enterprise Server 11 SP2:

      zypper in -t patch slessp2-libvirt-7310

   - SUSE Linux Enterprise Desktop 11 SP2:

      zypper in -t patch sledsp2-libvirt-7310

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64):

      libvirt-devel-0.9.6-0.25.1

   - SUSE Linux Enterprise Software Development Kit 11 SP2 (x86_64):

      libvirt-devel-32bit-0.9.6-0.25.1

   - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64):

      libvirt-0.9.6-0.25.1
      libvirt-client-0.9.6-0.25.1
      libvirt-doc-0.9.6-0.25.1
      libvirt-python-0.9.6-0.25.1

   - SUSE Linux Enterprise Server 11 SP2 (ppc64 s390x x86_64):

      libvirt-client-32bit-0.9.6-0.25.1

   - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64):

      libvirt-0.9.6-0.25.1
      libvirt-client-0.9.6-0.25.1
      libvirt-doc-0.9.6-0.25.1
      libvirt-python-0.9.6-0.25.1

   - SUSE Linux Enterprise Desktop 11 SP2 (x86_64):

      libvirt-client-32bit-0.9.6-0.25.1


References:

   https://www.suse.com/security/cve/CVE-2013-0170.html
   https://bugzilla.novell.com/782311
   https://bugzilla.novell.com/800976
   https://login.microfocus.com/nidp/app/login

SuSE: 2013:0320-1: important: libvirt

February 21, 2013
An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is ...

Summary

libvirt was updated to fix the following security issue: * A flaw was found in the way message freeing on connection cleanup was handled under certain error conditions. A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd or, potentially, escalate their privilages to that of libvirtd process. (CVE-2013-0170) Also following bug has been fixed: * Add managedSave functions to legacy xen driver bnc#782311 Security Issue reference: * CVE-2013-0170 Indications: Everyone should install this update. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11 SP2: zypper in -t patch sdksp2-libvirt-7310 - SUSE Linux Enterprise Server 11 SP2: zypper in -t patch slessp2-libvirt-7310 - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-libvirt-7310 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 11 SP2 (i586 ia64 ppc64 s390x x86_64): libvirt-devel-0.9.6-0.25.1 - SUSE Linux Enterprise Software Development Kit 11 SP2 (x86_64): libvirt-devel-32bit-0.9.6-0.25.1 - SUSE Linux Enterprise Server 11 SP2 (i586 ia64 ppc64 s390x x86_64): libvirt-0.9.6-0.25.1 libvirt-client-0.9.6-0.25.1 libvirt-doc-0.9.6-0.25.1 libvirt-python-0.9.6-0.25.1 - SUSE Linux Enterprise Server 11 SP2 (ppc64 s390x x86_64): libvirt-client-32bit-0.9.6-0.25.1 - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64): libvirt-0.9.6-0.25.1 libvirt-client-0.9.6-0.25.1 libvirt-doc-0.9.6-0.25.1 libvirt-python-0.9.6-0.25.1 - SUSE Linux Enterprise Desktop 11 SP2 (x86_64): libvirt-client-32bit-0.9.6-0.25.1

References

#782311 #800976

Cross- CVE-2013-0170

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP2

SUSE Linux Enterprise Server 11 SP2

SUSE Linux Enterprise Desktop 11 SP2

https://www.suse.com/security/cve/CVE-2013-0170.html

https://bugzilla.novell.com/782311

https://bugzilla.novell.com/800976

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2013:0320-1
Rating: important

Related News