[SECURITY] Fedora 20 Update: libvirt-1.1.3.8-1.fc20

updates at fedoraproject.org updates at fedoraproject.org
Sat Nov 22 12:37:22 UTC 2014


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2014-15228
2014-11-17 05:28:44
--------------------------------------------------------------------------------

Name        : libvirt
Product     : Fedora 20
Version     : 1.1.3.8
Release     : 1.fc20
URL         : http://libvirt.org/
Summary     : Library providing a simple virtualization API
Description :
Libvirt is a C toolkit to interact with the virtualization capabilities
of recent versions of Linux (and other OSes). The main package includes
the libvirtd server exporting the virtualization support.

--------------------------------------------------------------------------------
Update Information:

* Rebased to version 1.1.3.8
* CVE-2014-3633: out-of-bounds read in blockiotune (bz #1160823)
* CVE-2014-3657: Potential deadlock in domain_conf (bz #1160824)
* CVE-2014-7823: information leak with migratable flag (bz #1160822)
--------------------------------------------------------------------------------
ChangeLog:

* Sat Nov 15 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.8-1
- Rebased to version 1.1.3.8
- CVE-2014-3633: out-of-bounds read in blockiotune (bz #1160823)
- CVE-2014-3657: Potential deadlock in domain_conf (bz #1160824)
- CVE-2014-7823: information leak with migratable flag (bz #1160822)
* Thu Oct 30 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.6-2
- Fix USB device descriptions (bz #1138887)
* Mon Sep  8 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.6-1
- Rebased to version 1.1.3.6
- Fix memory leak in testDomainGenerateIfnames (bz 1135388)
- Fix python bindings graphics event enum (bz 1113612)
- Fix cflags in pkg-config --libs (bz 1134453)
- Fix pci bus naming for PPC (bz 1119401)
- Fix LXC user namespacess (bz 1105832)
- Fix possible 'unknown error' reporting from vol-dumpxml (bz 1097067)
* Mon May 19 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.5-2
- Fix xen hvm VNC port (bz #1094262)
- CVE-2014-0179: Unsafe XML parsing (bz #1094792, bz #1088290)
- Fix failure to start xen instances (rackspace in particular) (bz #1098376)
* Sat May  3 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.5-1
- Rebased to version 1.1.3.5
- Fix QXL PCI address conflict (bz #1016775)
- Fix journald PRIORITY values (bz #1043550)
- Fix crash with filterref and update-device (bz #1093301)
- Fix 'cannot find session' error with iscsi (bz #1093791)
- Fix bond XML issues (bz #1084702)
* Tue Mar 18 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.4-4
- Fix migration failure occurring with VIR_DOMAIN_XML_MIGRATABLE (bz #1075174)
* Mon Mar 10 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.4-3
- Escape XML characters in volume XML (bz #1074528)
* Wed Mar  5 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.4-2
- Fix libvirt-guests.service on host boot (bz #1031696)
* Tue Feb 18 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.4-1
- Rebased to version 1.1.3.4
- Fix domain events when ACLs are used (bz #1058839)
- CVE-2013-6456: unsafe usage of paths under /proc//root (bz #1048628, bz
* Sat Feb  1 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.3-5
- Rebuild again for openwsman soname bump
* Thu Jan 30 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.3-4
- Fix baselineCPU EXPAND_FEATURES (bz #1049391)
* Mon Jan 27 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.3-3
- Rebuild for openwsman soname bump
* Mon Jan 20 2014 Richard W.M. Jones <rjones at redhat.com> - 1.1.3.3-2
- Backport increase default qemu monitor timeout from 3 to 30
  seconds (bz #987088)
* Thu Jan 16 2014 Cole Robinson <crobinso at redhat.com> - 1.1.3.3-1
- Rebased to version 1.1.3.3
- Fix crash in virDBusAddWatch (bz #885445)
- Cleanup migration ports when migration is cancelled (bz #1018530)
- Fix virt-login-shell (bz #1054479)
- CVE-2013-6458 libvirt: qemu: job usage issue in several APIs leading to
  libvirtd crash (bz #1054206, bz #1048631)
- CVE-2013-6436 libvirt: crash in lxcDomainGetMemoryParameters (bz #1049136,
  bz #1042252)
- CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL (bz
* Sat Dec 14 2013 Cole Robinson <crobinso at redhat.com> - 1.1.3.2-1
- Rebased to version 1.1.3.2
- Fix occasional libvirt-guests.service startup failure (bz #906009)
- Fix hotplugging USB device to qemu VM (bz #1016511)
- Fix return code of baselineCPU python API (bz #1033039)
- Don't reload libvirt-guests when libvirt-client is updated (bz #962225)
- Fix infinite loop in libvirt_lxc (bz #1005570)
- Fix vdsm-tool segfault during vdsm startup (bz #1034312)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1141131 - CVE-2014-3633 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index
        https://bugzilla.redhat.com/show_bug.cgi?id=1141131
  [ 2 ] Bug #1145667 - CVE-2014-3657 libvirt: domain_conf: domain deadlock DoS
        https://bugzilla.redhat.com/show_bug.cgi?id=1145667
  [ 3 ] Bug #1160817 - CVE-2014-7823 libvirt: dumpxml: information leak with migratable flag
        https://bugzilla.redhat.com/show_bug.cgi?id=1160817
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use
su -c 'yum update libvirt' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list