Scientific Linux Security Update : libvirt on SL5.x i386/x86_64 (20130108)

low Nessus Plugin ID 63598

Synopsis

The remote Scientific Linux host is missing one or more security updates.

Description

Bus and device IDs were ignored when attempting to attach multiple USB devices with identical vendor or product IDs to a guest. This could result in the wrong device being attached to a guest, giving that guest root access to the device. (CVE-2012-2693)

This update also fixes the following bugs :

- Previously, the libvirtd library failed to set the autostart flags for already defined QEMU domains. This bug has been fixed, and the domains can now be successfully marked as autostarted.

- Prior to this update, the virFileAbsPath() function was not taking into account the slash ('/') directory separator when allocating memory for combining the cwd() function and a path. This behavior could lead to a memory corruption. With this update, a transformation to the virAsprintff() function has been introduced into virFileAbsPath(). As a result, the aforementioned behavior no longer occurs.

- With this update, a man page of the virsh user interface has been enhanced with information on the 'domxml-from-native' and 'domxml-to-native' commands. A correct notation of the format argument has been clarified. As a result, confusion is avoided when setting the format argument in the described commands.

After installing the updated packages, libvirtd will be restarted automatically.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?fea286d8

Plugin Details

Severity: Low

ID: 63598

File Name: sl_20130108_libvirt_on_SL5_x.nasl

Version: 1.5

Type: local

Agent: unix

Published: 1/17/2013

Updated: 1/14/2021

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Low

Base Score: 3.7

Vector: CVSS2#AV:L/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:fermilab:scientific_linux:libvirt, p-cpe:/a:fermilab:scientific_linux:libvirt-debuginfo, p-cpe:/a:fermilab:scientific_linux:libvirt-devel, p-cpe:/a:fermilab:scientific_linux:libvirt-python, x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 1/8/2013

Vulnerability Publication Date: 6/17/2012

Reference Information

CVE: CVE-2012-2693