Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2014.0243
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2014-0243)
Zusammenfassung:The remote host is missing an update for the 'libvirt' package(s) announced via the MGASA-2014-0243 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'libvirt' package(s) announced via the MGASA-2014-0243 advisory.

Vulnerability Insight:
Updated libvirt packages fix security vulnerabilities:

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through
1.2.1 allows local users to (1) delete arbitrary host devices
via the virDomainDeviceDettach API and a symlink attack on /dev
in the container, (2) create arbitrary nodes (mknod) via the
virDomainDeviceAttach API and a symlink attack on /dev in the
container, and cause a denial of service (shutdown or reboot host
OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a
symlink attack on /dev/initctl in the container, related to paths under
/proc//root and the virInitctlSetRunLevel function (CVE-2013-6456).

libvirt was patched to prevent expansion of entities when parsing XML
files. This vulnerability allowed malicious users to read arbitrary
files or cause a denial of service (CVE-2014-0179).

Affected Software/OS:
'libvirt' package(s) on Mageia 3, Mageia 4.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:A/AC:M/Au:S/C:N/I:P/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-6456
56187
http://secunia.com/advisories/56187
56215
http://secunia.com/advisories/56215
60895
http://secunia.com/advisories/60895
65743
http://www.securityfocus.com/bid/65743
FEDORA-2014-2864
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129199.html
GLSA-201412-04
http://security.gentoo.org/glsa/glsa-201412-04.xml
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=5fc590ad9f4
http://libvirt.org/news.html
http://security.libvirt.org/2013/0018.html
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=732394
https://bugzilla.redhat.com/show_bug.cgi?id=1045643
openSUSE-SU-2014:0593
http://lists.opensuse.org/opensuse-updates/2014-05/msg00004.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-0179
DSA-3038
http://www.debian.org/security/2014/dsa-3038
RHSA-2014:0560
http://rhn.redhat.com/errata/RHSA-2014-0560.html
USN-2366-1
http://www.ubuntu.com/usn/USN-2366-1
http://security.libvirt.org/2014/0003.html
openSUSE-SU-2014:0650
http://lists.opensuse.org/opensuse-updates/2014-05/msg00048.html
openSUSE-SU-2014:0674
http://lists.opensuse.org/opensuse-updates/2014-05/msg00052.html
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.