Sponsored Content
Special Forums Cybersecurity Security Advisories (RSS) USN-694-1: libvirt vulnerability Post 302269491 by Linux Bot on Wednesday 17th of December 2008 07:50:05 PM
Old 12-17-2008
USN-694-1: libvirt vulnerability

Referenced CVEs:
CVE-2008-5086


Description:
===========================================================Ubuntu Security Notice USN-694-1 December 18, 2008libvirt vulnerabilityCVE-2008-5086===========================================================A security issue affects the following Ubuntu releases:Ubuntu 7.10Ubuntu 8.04 LTSUbuntu 8.10This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 7.10: libvirt0 0.3.0-0ubuntu2.1Ubuntu 8.04 LTS: libvirt0 0.4.0-2ubuntu8.1Ubuntu 8.10: libvirt0 0.4.4-3ubuntu3.1In general, a standard system upgrade is sufficient to effect thenecessary changes.Details follow:It was discovered that libvirt did not mark certain operations as read-only. Alocal attacker may be able to perform privileged actions such as migratingvirtual machines, adjusting autostart flags, or accessing privileged data inthe virtual machine memory and disks.





More...
 
VIRT-PKI-VALIDATE(1)					      Virtualization Support					      VIRT-PKI-VALIDATE(1)

NAME
virt-pki-validate - validate libvirt PKI files are configured correctly SYNOPSIS
virt-pki-validate DESCRIPTION
This tool validates that the necessary PKI files are configured for a secure libvirt server or client using the TLS encryption protocol. It will report any missing certificate or key files on the host. It should be run as root to ensure it can read all the necessary files EXIT STATUS
Upon successful validation, an exit status of 0 will be set. Upon failure a non-zero status will be set. AUTHOR
Richard Jones BUGS
Report any bugs discovered to the libvirt community via the mailing list "http://libvirt.org/contact.html" or bug tracker "http://libvirt.org/bugs.html". Alternatively report bugs to your software distributor / vendor. COPYRIGHT
Copyright (C) 2006-2010 by Red Hat, Inc. LICENSE
virt-pki-validate is distributed under the terms of the GNU GPL v2+. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE SEE ALSO
virsh(1), online PKI setup instructions "http://libvirt.org/remote.html" libvirt-0.8.1 2010-07-05 VIRT-PKI-VALIDATE(1)
All times are GMT -4. The time now is 08:22 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy