Release date:
Updated on:
Affected Systems:
Debian Linux 5.0 x
RedHat Fedora 15
RedHat Fedora 14
RedHat Fedora 13
Ubuntu Linux
Libvirt
Description:
--------------------------------------------------------------------------------
Bugtraq id: 46820
Cve id: CVE-2010-4746, CVE-2011-1146
Libvirt is a free and open-source C function library that supports mainstream virtualization tools in Linux.
Multiple Remote Denial-of-Service vulnerabilities exist in libvirt implementation. Remote attackers can exploit these vulnerabilities to cause application crash in the affected database and cause denial-of-service to legitimate users.
Multiple libvirt API calls (virNodeDeviceDettach, virNodeDeviceReset, virNodeDeviceReAttach, disconnect, virDomainSnapshotDelete, and virConnectDomainXMLToNative) do not execute read-only connections. Local attackers can exploit this vulnerability to deny or escalate server Permissions.
<* Source: Petr Matousek
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 683650
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ubuntu
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ubuntulinux.org/