http://www.mandriva.com/en/
______________________________
Package : libvirt
Date : November 21, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
Updated libvirt packages fix security vulnerability:
Eric Blake discovered that libvirt incorrectly handled permissions
when processing the qemuDomainFormatXML command. An attacker with
read-only privileges could possibly use this to gain access to certain
information from the domain xml file (CVE-2014-7823).
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
______________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
5ed33aeb5e6047ef2c44eaad86c5ab
95ef6a118a122f3788d70269711a14
660e0b7522f6d8fff06ec1a1bdd812
65331217fc5523ca0c57bc4d5934bd
e4c2ee163616b3109e24e548872c32
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą