[SECURITY] Fedora 20 Update: libvirt-1.1.3.3-1.fc20

updates at fedoraproject.org updates at fedoraproject.org
Tue Jan 21 05:56:08 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-1042
2014-01-18 02:56:32
--------------------------------------------------------------------------------

Name        : libvirt
Product     : Fedora 20
Version     : 1.1.3.3
Release     : 1.fc20
URL         : http://libvirt.org/
Summary     : Library providing a simple virtualization API
Description :
Libvirt is a C toolkit to interact with the virtualization capabilities
of recent versions of Linux (and other OSes). The main package includes
the libvirtd server exporting the virtualization support.

--------------------------------------------------------------------------------
Update Information:

* Rebased to version 1.1.3.3
* Fix crash in virDBusAddWatch (bz #885445)
* Cleanup migration ports when migration is cancelled (bz #1018530)
* Fix virt-login-shell (bz #1054479)
* CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to libvirtd crash (bz #1054206, bz #1048631)
* CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters (bz #1049136, bz #1042252)
* CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL (bz #1054203, bz #1048637)
* CVE-2014-1447: libvirt: denial of service with keepalive (bz 1052957, bz 1054808)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jan 16 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.3-1
- Rebased to version 1.1.3.3
- Fix crash in virDBusAddWatch (bz #885445)
- Cleanup migration ports when migration is cancelled (bz #1018530)
- Fix virt-login-shell (bz #1054479)
- CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to
  libvirtd crash (bz #1054206, bz #1048631)
- CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters (bz #1049136,
  bz #1042252)
- CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL (bz
* Sat Dec 14 2013 Cole Robinson <crobinso at redhat.com> - 1.1.3.2-1
- Rebased to version 1.1.3.2
- Fix occasional libvirt-guests.service startup failure (bz #906009)
- Fix hotplugging USB device to qemu VM (bz #1016511)
- Fix return code of baselineCPU python API (bz #1033039)
- Don't reload libvirt-guests when libvirt-client is updated (bz #962225)
- Fix infinite loop in libvirt_lxc (bz #1005570)
- Fix vdsm-tool segfault during vdsm startup (bz #1034312)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #885445 - f18/f19/f20 crash in virDBusWatchCallback on i686
        https://bugzilla.redhat.com/show_bug.cgi?id=885445
  [ 2 ] Bug #1054479 - virt-login-shell busted after fix for CVE-2013-4400
        https://bugzilla.redhat.com/show_bug.cgi?id=1054479
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update libvirt' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list