Scientific Linux Security Update : libvirt on SL6.x i386/x86_64

Medium Nessus Plugin ID 64953


The remote Scientific Linux host is missing one or more security updates.


It was discovered that libvirt made certain invalid assumptions about dnsmasq's command line options when setting up DNS masquerading for virtual machines, resulting in dnsmasq incorrectly processing network packets from network interfaces that were intended to be prohibited.
This update includes the changes necessary to call dnsmasq with a new command line option, which was introduced to dnsmasq via SLSA-2013:0277. (CVE-2012-3411)

In order for libvirt to be able to make use of the new command line option (--bind-dynamic), updated dnsmasq packages need to be installed. Refer to SLSA-2013:0277 for additional information.

After installing the updated packages, libvirtd must be restarted ('service libvirtd restart') for this update to take effect.


Update the affected packages.

See Also

Plugin Details

Severity: Medium

ID: 64953

File Name: sl_20130221_libvirt_on_SL6_x.nasl

Version: $Revision: 1.2 $

Type: local

Agent: unix

Published: 2013/03/01

Modified: 2013/03/07

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: x-cpe:/o:fermilab:scientific_linux

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 2013/02/21

Reference Information

CVE: CVE-2012-3411