Debian DSA-4137-1 : libvirt - security update

high Nessus Plugin ID 108346

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities were discovered in Libvirt, a virtualisation abstraction library :

- CVE-2018-1064 Daniel Berrange discovered that the QEMU guest agent performed insufficient validation of incoming data, which allows a privileged user in the guest to exhaust resources on the virtualisation host, resulting in denial of service.

- CVE-2018-5748 Daniel Berrange and Peter Krempa discovered that the QEMU monitor was susceptible to denial of service by memory exhaustion. This was already fixed in Debian stretch and only affects Debian jessie.

- CVE-2018-6764 Pedro Sampaio discovered that LXC containers detected the hostname insecurely. This only affects Debian stretch.

Solution

Upgrade the libvirt packages.

For the oldstable distribution (jessie), these problems have been fixed in version 1.2.9-9+deb8u5.

For the stable distribution (stretch), these problems have been fixed in version 3.0.0-4+deb9u3.

See Also

https://security-tracker.debian.org/tracker/CVE-2018-1064

https://security-tracker.debian.org/tracker/CVE-2018-5748

https://security-tracker.debian.org/tracker/CVE-2018-6764

https://security-tracker.debian.org/tracker/source-package/libvirt

https://packages.debian.org/source/jessie/libvirt

https://packages.debian.org/source/stretch/libvirt

https://www.debian.org/security/2018/dsa-4137

Plugin Details

Severity: High

ID: 108346

File Name: debian_DSA-4137.nasl

Version: 1.5

Type: local

Agent: unix

Published: 3/15/2018

Updated: 11/13/2018

Supported Sensors: Frictionless Assessment Agent, Nessus Agent

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS v3

Risk Factor: High

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:libvirt, cpe:/o:debian:debian_linux:8.0, cpe:/o:debian:debian_linux:9.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 3/14/2018

Reference Information

CVE: CVE-2018-1064, CVE-2018-5748, CVE-2018-6764

DSA: 4137