=========================================================================Ubuntu Security Notice USN-4047-2
January 13, 2020

libvirt vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in libvirt.

Software Description:
- libvirt: Libvirt virtualization toolkit

Details:

USN-4047-1 fixed a vulnerability in libvirt. This update provides
the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

 Matthias Gerstner and Ján Tomko discovered that libvirt incorrectly handled
 certain API calls. An attacker could possibly use this issue to check for
 arbitrary files, or execute arbitrary binaries. In the default
 installation, attackers would be isolated by the libvirt AppArmor profile.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
  libvirt-bin                     1.2.2-0ubuntu13.1.28+esm1
  libvirt0                        1.2.2-0ubuntu13.1.28+esm1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4047-2
  https://ubuntu.com/security/notices/USN-4047-1
  CVE-2019-10161

Ubuntu 4047-2: libvirt update vulnerability

January 13, 2020
Several security issues were fixed in libvirt.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: libvirt-bin 1.2.2-0ubuntu13.1.28+esm1 libvirt0 1.2.2-0ubuntu13.1.28+esm1 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4047-2

https://ubuntu.com/security/notices/USN-4047-1

CVE-2019-10161

Severity
January 13, 2020

Package Information

Related News