Oval Definition:oval:com.redhat.rhsa:def:20162576
Revision Date:2016-11-03Version:638
Title:RHSA-2016:2576: libguestfs and virt-p2v security, bug fix, and enhancement update (Moderate)
Description:The libguestfs packages contain a library, which is used for accessing and modifying virtual machine (VM) disk images.

Virt-p2v is a tool for conversion of a physical server to a virtual guest.

  • The following packages have been upgraded to a newer upstream version: libguestfs (1.32.7), virt-p2v (1.32.7). (BZ#1218766)

    Security Fix(es):

  • An integer conversion flaw was found in the way OCaml's String handled its length. Certain operations on an excessively long String could trigger a buffer overflow or result in an information leak. (CVE-2015-8869)

    Note: The libguestfs packages in this advisory were rebuilt with a fixed version of OCaml to address this issue.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-8869
    RHSA-2016:2576
    RHSA-2016:2576-01
    RHSA-2016:2576-02
    RHSA-2016:2576-02
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • virt-p2v is earlier than 0:1.32.7-2.el7
  • AND virt-p2v is signed with Red Hat redhatrelease2 key
  • libguestfs is earlier than 1:1.32.7-3.el7
  • AND libguestfs is signed with Red Hat redhatrelease2 key
  • libguestfs-bash-completion is earlier than 1:1.32.7-3.el7
  • AND libguestfs-bash-completion is signed with Red Hat redhatrelease2 key
  • libguestfs-devel is earlier than 1:1.32.7-3.el7
  • AND libguestfs-devel is signed with Red Hat redhatrelease2 key
  • libguestfs-gfs2 is earlier than 1:1.32.7-3.el7
  • AND libguestfs-gfs2 is signed with Red Hat redhatrelease2 key
  • libguestfs-gobject is earlier than 1:1.32.7-3.el7
  • AND libguestfs-gobject is signed with Red Hat redhatrelease2 key
  • libguestfs-gobject-devel is earlier than 1:1.32.7-3.el7
  • AND libguestfs-gobject-devel is signed with Red Hat redhatrelease2 key
  • libguestfs-gobject-doc is earlier than 1:1.32.7-3.el7
  • AND libguestfs-gobject-doc is signed with Red Hat redhatrelease2 key
  • libguestfs-inspect-icons is earlier than 1:1.32.7-3.el7
  • AND libguestfs-inspect-icons is signed with Red Hat redhatrelease2 key
  • libguestfs-java is earlier than 1:1.32.7-3.el7
  • AND libguestfs-java is signed with Red Hat redhatrelease2 key
  • libguestfs-java-devel is earlier than 1:1.32.7-3.el7
  • AND libguestfs-java-devel is signed with Red Hat redhatrelease2 key
  • libguestfs-javadoc is earlier than 1:1.32.7-3.el7
  • AND libguestfs-javadoc is signed with Red Hat redhatrelease2 key
  • libguestfs-man-pages-ja is earlier than 1:1.32.7-3.el7
  • AND libguestfs-man-pages-ja is signed with Red Hat redhatrelease2 key
  • libguestfs-man-pages-uk is earlier than 1:1.32.7-3.el7
  • AND libguestfs-man-pages-uk is signed with Red Hat redhatrelease2 key
  • libguestfs-rescue is earlier than 1:1.32.7-3.el7
  • AND libguestfs-rescue is signed with Red Hat redhatrelease2 key
  • libguestfs-rsync is earlier than 1:1.32.7-3.el7
  • AND libguestfs-rsync is signed with Red Hat redhatrelease2 key
  • libguestfs-tools is earlier than 1:1.32.7-3.el7
  • AND libguestfs-tools is signed with Red Hat redhatrelease2 key
  • libguestfs-tools-c is earlier than 1:1.32.7-3.el7
  • AND libguestfs-tools-c is signed with Red Hat redhatrelease2 key
  • libguestfs-xfs is earlier than 1:1.32.7-3.el7
  • AND libguestfs-xfs is signed with Red Hat redhatrelease2 key
  • lua-guestfs is earlier than 1:1.32.7-3.el7
  • AND lua-guestfs is signed with Red Hat redhatrelease2 key
  • ocaml-libguestfs is earlier than 1:1.32.7-3.el7
  • AND ocaml-libguestfs is signed with Red Hat redhatrelease2 key
  • ocaml-libguestfs-devel is earlier than 1:1.32.7-3.el7
  • AND ocaml-libguestfs-devel is signed with Red Hat redhatrelease2 key
  • perl-Sys-Guestfs is earlier than 1:1.32.7-3.el7
  • AND perl-Sys-Guestfs is signed with Red Hat redhatrelease2 key
  • python-libguestfs is earlier than 1:1.32.7-3.el7
  • AND python-libguestfs is signed with Red Hat redhatrelease2 key
  • ruby-libguestfs is earlier than 1:1.32.7-3.el7
  • AND ruby-libguestfs is signed with Red Hat redhatrelease2 key
  • virt-dib is earlier than 1:1.32.7-3.el7
  • AND virt-dib is signed with Red Hat redhatrelease2 key
  • virt-v2v is earlier than 1:1.32.7-3.el7
  • AND virt-v2v is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • virt-p2v is earlier than 0:1.32.7-2.el7
  • AND virt-p2v is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-bash-completion is earlier than 1:1.32.7-3.el7
  • AND libguestfs-bash-completion is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-man-pages-ja is earlier than 1:1.32.7-3.el7
  • AND libguestfs-man-pages-ja is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-javadoc is earlier than 1:1.32.7-3.el7
  • AND libguestfs-javadoc is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-man-pages-uk is earlier than 1:1.32.7-3.el7
  • AND libguestfs-man-pages-uk is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-gobject-doc is earlier than 1:1.32.7-3.el7
  • AND libguestfs-gobject-doc is signed with Red Hat redhatrelease2 key
  • OR
  • virt-dib is earlier than 1:1.32.7-3.el7
  • AND virt-dib is signed with Red Hat redhatrelease2 key
  • OR
  • ocaml-libguestfs-devel is earlier than 1:1.32.7-3.el7
  • AND ocaml-libguestfs-devel is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-rescue is earlier than 1:1.32.7-3.el7
  • AND libguestfs-rescue is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-gobject is earlier than 1:1.32.7-3.el7
  • AND libguestfs-gobject is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-java-devel is earlier than 1:1.32.7-3.el7
  • AND libguestfs-java-devel is signed with Red Hat redhatrelease2 key
  • OR
  • lua-guestfs is earlier than 1:1.32.7-3.el7
  • AND lua-guestfs is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-gfs2 is earlier than 1:1.32.7-3.el7
  • AND libguestfs-gfs2 is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-devel is earlier than 1:1.32.7-3.el7
  • AND libguestfs-devel is signed with Red Hat redhatrelease2 key
  • OR
  • ocaml-libguestfs is earlier than 1:1.32.7-3.el7
  • AND ocaml-libguestfs is signed with Red Hat redhatrelease2 key
  • OR
  • ruby-libguestfs is earlier than 1:1.32.7-3.el7
  • AND ruby-libguestfs is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-gobject-devel is earlier than 1:1.32.7-3.el7
  • AND libguestfs-gobject-devel is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-rsync is earlier than 1:1.32.7-3.el7
  • AND libguestfs-rsync is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-inspect-icons is earlier than 1:1.32.7-3.el7
  • AND libguestfs-inspect-icons is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-tools is earlier than 1:1.32.7-3.el7
  • AND libguestfs-tools is signed with Red Hat redhatrelease2 key
  • OR
  • perl-Sys-Guestfs is earlier than 1:1.32.7-3.el7
  • AND perl-Sys-Guestfs is signed with Red Hat redhatrelease2 key
  • OR
  • python-libguestfs is earlier than 1:1.32.7-3.el7
  • AND python-libguestfs is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-xfs is earlier than 1:1.32.7-3.el7
  • AND libguestfs-xfs is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs is earlier than 1:1.32.7-3.el7
  • AND libguestfs is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-java is earlier than 1:1.32.7-3.el7
  • AND libguestfs-java is signed with Red Hat redhatrelease2 key
  • OR
  • libguestfs-tools-c is earlier than 1:1.32.7-3.el7
  • AND libguestfs-tools-c is signed with Red Hat redhatrelease2 key
  • OR
  • virt-v2v is earlier than 1:1.32.7-3.el7
  • AND virt-v2v is signed with Red Hat redhatrelease2 key
  • BACK