Oval Definition:oval:org.opensuse.security:def:63713
Revision Date:2020-12-01Version:1
Title:Security update for libvirt (Important)
Description:

This update for libvirt fixes the following issues:

Security issues fixed:

- CVE-2019-10161: Fixed virDomainSaveImageGetXMLDesc API which could accept a path parameter pointing anywhere on the system and potentially leading to execution of a malicious file with root privileges by libvirtd (bsc#1138301). - CVE-2019-10166: Fixed an issue with virDomainManagedSaveDefineXML which could have been used to alter the domain's config used for managedsave or execute arbitrary emulator binaries (bsc#1138302). - CVE-2019-10167: Fixed an issue with virConnectGetDomainCapabilities API which could have been used to execute arbitrary emulators (bsc#1138303).
Family:unixClass:patch
Status:Reference(s):1047238
1050911
1051510
1054914
1055117
1056686
1060662
1061840
1061843
1064597
1064701
1065600
1065729
1066369
1071009
1071306
1071995
1078248
1082555
1085030
1085536
1085539
1086103
1087092
1090734
1091171
1093205
1102097
1104902
1104967
1106061
1106284
1106434
1108382
1109158
1112178
1112894
1112899
1112902
1112903
1112905
1112906
1112907
1113722
1114279
1114542
1114592
1118689
1119086
1120374
1120876
1120902
1120937
1122983
1123034
1123105
1123959
1124370
1125330
1127987
1127988
1129424
1129519
1129664
1129821
1130262
1131107
1131281
1131304
1131565
1133021
1134291
1134881
1134882
1135219
1135254
1135642
1135897
1136261
1137069
1137835
1137865
1137884
1137959
1138301
1138302
1138303
1138539
1139020
1139021
1139101
1139500
1139885
1139886
1140012
1140100
1140102
1140103
1140106
1140110
1140111
1140155
1140426
1140487
1140501
1140513
1140534
1140538
1140554
1140664
1140666
1140669
1140673
1141013
1141171
1141450
1141543
1141554
1141897
1142019
1142076
1142109
1142117
1142118
1142119
1142496
1142541
1142635
1142649
1142654
1142685
1142701
1142857
1143300
1143466
1143478
1143765
1143841
1143843
1144123
1144333
1144474
1144518
1144718
1144813
1144880
1144886
1144912
1144920
1144979
1145010
1145024
1145051
1145059
1145134
1145189
1145235
1145300
1145302
1145388
1145389
1145390
1145391
1145392
1145393
1145394
1145395
1145396
1145397
1145408
1145409
1145661
1145678
1145687
1145920
1145922
1145934
1145937
1145940
1145941
1145942
1146042
1146074
1146084
1146163
1146285
1146346
1146351
1146352
1146361
1146376
1146378
1146381
1146391
1146399
1146413
1146425
1146512
1146514
1146516
1146519
1146524
1146526
1146529
1146531
1146540
1146543
1146547
1146550
1146575
1146589
1146664
1146678
1146938
1148031
1148032
1148033
1148034
1148035
1148093
1148133
1148192
1148196
1148198
1148202
1148303
1148363
1148379
1148394
1148517
1148527
1148574
1148616
1148617
1148619
1148698
1148712
1148859
1148868
1149053
1149083
1149104
1149105
1149106
1149145
1149197
1149214
1149224
1149313
1149325
1149376
1149413
1149418
1149424
1149446
1149522
1149527
1149539
1149552
1149555
1149591
1149602
1149612
1149626
1149651
1149652
1149713
1149940
1149959
1149963
1149976
1150025
1150033
1150112
1150381
1150423
1150562
1150727
1150860
1150861
1150933
1151350
1151610
1151667
1151671
1151891
1151955
1152024
1152025
1152026
1152161
1152325
1152457
1152460
1152466
1152972
1152974
1152975
1168326
1168352
1172177
1172798
1172846
1173674
1173972
1174753
1174817
1175168
CVE-2017-18551
CVE-2017-18595
CVE-2018-18335
CVE-2018-18356
CVE-2018-18500
CVE-2018-18501
CVE-2018-18505
CVE-2018-18506
CVE-2018-20976
CVE-2018-21008
CVE-2019-10161
CVE-2019-10166
CVE-2019-10167
CVE-2019-10207
CVE-2019-12779
CVE-2019-12974
CVE-2019-12975
CVE-2019-12976
CVE-2019-12978
CVE-2019-12979
CVE-2019-13133
CVE-2019-13134
CVE-2019-13135
CVE-2019-13295
CVE-2019-13297
CVE-2019-13300
CVE-2019-13301
CVE-2019-13307
CVE-2019-13308
CVE-2019-13310
CVE-2019-13311
CVE-2019-13391
CVE-2019-13454
CVE-2019-14250
CVE-2019-14814
CVE-2019-14815
CVE-2019-14816
CVE-2019-14821
CVE-2019-14835
CVE-2019-15030
CVE-2019-15031
CVE-2019-15090
CVE-2019-15098
CVE-2019-15117
CVE-2019-15118
CVE-2019-15211
CVE-2019-15212
CVE-2019-15214
CVE-2019-15215
CVE-2019-15216
CVE-2019-15217
CVE-2019-15218
CVE-2019-15219
CVE-2019-15220
CVE-2019-15221
CVE-2019-15222
CVE-2019-15239
CVE-2019-15290
CVE-2019-15291
CVE-2019-15292
CVE-2019-15538
CVE-2019-15666
CVE-2019-15847
CVE-2019-15902
CVE-2019-15917
CVE-2019-15919
CVE-2019-15920
CVE-2019-15921
CVE-2019-15924
CVE-2019-15926
CVE-2019-15927
CVE-2019-5785
CVE-2019-9456
CVE-2019-9506
CVE-2019-9788
CVE-2019-9790
CVE-2019-9791
CVE-2019-9792
CVE-2019-9793
CVE-2019-9794
CVE-2019-9795
CVE-2019-9796
CVE-2019-9801
CVE-2019-9810
CVE-2019-9813
CVE-2020-13844
CVE-2020-15503
CVE-2020-7064
CVE-2020-7066
CVE-2020-8164
openSUSE-SU-2019:1752-1
openSUSE-SU-2020:0642-1
openSUSE-SU-2020:1128-1
openSUSE-SU-2020:1533-1
SUSE-SU-2019:0336-1
SUSE-SU-2019:0852-1
SUSE-SU-2019:1599-1
SUSE-SU-2019:2010-1
SUSE-SU-2019:2648-1
SUSE-SU-2020:0394-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libqb-1.0.3+20190326.a521604-lp151.2.3 is installed
  • OR libqb-devel-1.0.3+20190326.a521604-lp151.2.3 is installed
  • OR libqb-devel-32bit-1.0.3+20190326.a521604-lp151.2.3 is installed
  • OR libqb-tests-1.0.3+20190326.a521604-lp151.2.3 is installed
  • OR libqb-tools-1.0.3+20190326.a521604-lp151.2.3 is installed
  • OR libqb20-1.0.3+20190326.a521604-lp151.2.3 is installed
  • OR libqb20-32bit-1.0.3+20190326.a521604-lp151.2.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libraw-0.18.9-lp152.5.3 is installed
  • OR libraw-devel-0.18.9-lp152.5.3 is installed
  • OR libraw-devel-static-0.18.9-lp152.5.3 is installed
  • OR libraw-tools-0.18.9-lp152.5.3 is installed
  • OR libraw16-0.18.9-lp152.5.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libvirt-4.0.0-8.15 is installed
  • OR libvirt-admin-4.0.0-8.15 is installed
  • OR libvirt-client-4.0.0-8.15 is installed
  • OR libvirt-daemon-4.0.0-8.15 is installed
  • OR libvirt-daemon-config-network-4.0.0-8.15 is installed
  • OR libvirt-daemon-config-nwfilter-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-interface-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-libxl-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-lxc-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-network-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-nodedev-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-nwfilter-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-qemu-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-secret-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-storage-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-storage-core-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-storage-disk-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-storage-iscsi-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-storage-logical-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-storage-mpath-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-storage-rbd-4.0.0-8.15 is installed
  • OR libvirt-daemon-driver-storage-scsi-4.0.0-8.15 is installed
  • OR libvirt-daemon-hooks-4.0.0-8.15 is installed
  • OR libvirt-daemon-lxc-4.0.0-8.15 is installed
  • OR libvirt-daemon-qemu-4.0.0-8.15 is installed
  • OR libvirt-daemon-xen-4.0.0-8.15 is installed
  • OR libvirt-doc-4.0.0-8.15 is installed
  • OR libvirt-libs-4.0.0-8.15 is installed
  • OR libvirt-lock-sanlock-4.0.0-8.15 is installed
  • OR libvirt-nss-4.0.0-8.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • gcc10-10.2.1+git583-1.3 is installed
  • OR libasan6-10.2.1+git583-1.3 is installed
  • OR libasan6-32bit-10.2.1+git583-1.3 is installed
  • OR libatomic1-10.2.1+git583-1.3 is installed
  • OR libatomic1-32bit-10.2.1+git583-1.3 is installed
  • OR libgcc_s1-10.2.1+git583-1.3 is installed
  • OR libgcc_s1-32bit-10.2.1+git583-1.3 is installed
  • OR libgfortran5-10.2.1+git583-1.3 is installed
  • OR libgfortran5-32bit-10.2.1+git583-1.3 is installed
  • OR libgo16-10.2.1+git583-1.3 is installed
  • OR libgo16-32bit-10.2.1+git583-1.3 is installed
  • OR libgomp1-10.2.1+git583-1.3 is installed
  • OR libgomp1-32bit-10.2.1+git583-1.3 is installed
  • OR libitm1-10.2.1+git583-1.3 is installed
  • OR libitm1-32bit-10.2.1+git583-1.3 is installed
  • OR liblsan0-10.2.1+git583-1.3 is installed
  • OR libobjc4-10.2.1+git583-1.3 is installed
  • OR libobjc4-32bit-10.2.1+git583-1.3 is installed
  • OR libquadmath0-10.2.1+git583-1.3 is installed
  • OR libquadmath0-32bit-10.2.1+git583-1.3 is installed
  • OR libstdc++6-10.2.1+git583-1.3 is installed
  • OR libstdc++6-32bit-10.2.1+git583-1.3 is installed
  • OR libstdc++6-locale-10.2.1+git583-1.3 is installed
  • OR libstdc++6-pp-gcc10-10.2.1+git583-1.3 is installed
  • OR libstdc++6-pp-gcc10-32bit-10.2.1+git583-1.3 is installed
  • OR libtsan0-10.2.1+git583-1.3 is installed
  • OR libubsan1-10.2.1+git583-1.3 is installed
  • OR libubsan1-32bit-10.2.1+git583-1.3 is installed
  • BACK