Oval Definition:oval:org.opensuse.security:def:80787
Revision Date:2019-08-09Version:1
Title:Security update for libvirt (Important)
Description:

This update for libvirt fixes the following issues:

Security issues fixed:

- CVE-2019-10161: Fixed virDomainSaveImageGetXMLDesc API which could accept a path parameter pointing anywhere on the system and potentially leading to execution of a malicious file with root privileges by libvirtd (bsc#1138301). - CVE-2019-10167: Fixed an issue with virConnectGetDomainCapabilities API which could have been used to execute arbitrary emulators (bsc#1138303).

Non-security issue fixed:

- qemu: Add support for overriding max threads per process limit (bsc#1133719)
Family:unixClass:patch
Status:Reference(s):1133719
1138301
1138303
CVE-2019-10161
CVE-2019-10167
SUSE-SU-2019:2105-1
Platform(s):SUSE OpenStack Cloud 7
Product(s):
Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • libvirt-2.0.0-27.61.1 is installed
  • OR libvirt-client-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-config-network-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-config-nwfilter-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-driver-interface-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-driver-libxl-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-driver-lxc-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-driver-network-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-driver-nodedev-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-driver-nwfilter-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-driver-qemu-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-driver-secret-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-driver-storage-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-hooks-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-lxc-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-qemu-2.0.0-27.61.1 is installed
  • OR libvirt-daemon-xen-2.0.0-27.61.1 is installed
  • OR libvirt-doc-2.0.0-27.61.1 is installed
  • OR libvirt-lock-sanlock-2.0.0-27.61.1 is installed
  • OR libvirt-nss-2.0.0-27.61.1 is installed
  • BACK