[USN-4047-2] libvirt update vulnerability

Leonidas S. Barbosa leo.barbosa at canonical.com
Mon Jan 13 15:59:39 UTC 2020


==========================================================================
Ubuntu Security Notice USN-4047-2
January 13, 2020

libvirt vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in libvirt.

Software Description:
- libvirt: Libvirt virtualization toolkit

Details:

USN-4047-1 fixed a vulnerability in libvirt. This update provides
the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

 Matthias Gerstner and Ján Tomko discovered that libvirt incorrectly handled
 certain API calls. An attacker could possibly use this issue to check for
 arbitrary files, or execute arbitrary binaries. In the default
 installation, attackers would be isolated by the libvirt AppArmor profile.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
  libvirt-bin                     1.2.2-0ubuntu13.1.28+esm1
  libvirt0                        1.2.2-0ubuntu13.1.28+esm1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://usn.ubuntu.com/4047-2
  https://usn.ubuntu.com/4047-1
  CVE-2019-10161
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20200113/1f85cae3/attachment.sig>


More information about the ubuntu-security-announce mailing list