Scientific Linux Security Update : libvirt on SL6.x i386/x86_64
Medium Nessus Plugin ID 64953
SynopsisThe remote Scientific Linux host is missing one or more security updates.
DescriptionIt was discovered that libvirt made certain invalid assumptions about dnsmasq's command line options when setting up DNS masquerading for virtual machines, resulting in dnsmasq incorrectly processing network packets from network interfaces that were intended to be prohibited.
This update includes the changes necessary to call dnsmasq with a new command line option, which was introduced to dnsmasq via SLSA-2013:0277. (CVE-2012-3411)
In order for libvirt to be able to make use of the new command line option (--bind-dynamic), updated dnsmasq packages need to be installed. Refer to SLSA-2013:0277 for additional information.
After installing the updated packages, libvirtd must be restarted ('service libvirtd restart') for this update to take effect.
SolutionUpdate the affected packages.