| Summary: | qemu new security issue CVE-2013-2007 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | sysadmin-bugs |
| Version: | 3 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/552861/ | ||
| Whiteboard: | MGA2TOO has_procedure mga3-64-ok mga3-32-ok mga2-32-ok mga2-64-ok | ||
| Source RPM: | qemu-1.2.0-8.mga3.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2013-06-04 20:39:00 CEST
David Walser
2013-06-04 20:44:38 CEST
Whiteboard:
(none) =>
MGA2TOO Testing complete mga3 64 Before ------ Found basic help with qemu-ga --help Confirmed with.. $ qemu-ga -d -v -l ~/test/qemu-ga.log -f ~/test/qemu-ga.pid $ ll test total 8 -rw-rw-rw- 1 claire claire 78 Jun 5 15:58 qemu-ga.log -rw------- 1 claire claire 4 Jun 5 15:58 qemu-ga.pid After ----- $ rm -f test/* $ qemu-ga -d -v -l ~/test/qemu-ga.log -f ~/test/qemu-ga.pid $ ll test total 8 -rw------- 1 claire claire 78 Jun 5 16:09 qemu-ga.log -rw------- 1 claire claire 5 Jun 5 16:09 qemu-ga.pid Also installed the dualcd in virt-manager Whiteboard:
MGA2TOO =>
MGA2TOO has_procedure mga3-64-ok Testing mga2 32 It doesn't appear to be affected to the same degree. Before ------ $ qemu-ga -d -v -l ~/test/qemu-ga.log -f ~/test/qemu-ga.pid $ ll test total 8 -rw-r--r-- 1 claire claire 78 Jun 5 16:18 qemu-ga.log -rw------- 1 claire claire 4 Jun 5 16:18 qemu-ga.pid After ----- $ rm -f test/* $ qemu-ga -d -v -l ~/test/qemu-ga.log -f ~/test/qemu-ga.pid $ ll test total 8 -rw-r--r-- 1 claire claire 78 Jun 5 16:20 qemu-ga.log -rw------- 1 claire claire 4 Jun 5 16:20 qemu-ga.pid The update doesn't appear to make any difference, could you check David please. Whiteboard:
MGA2TOO has_procedure mga3-64-ok =>
MGA2TOO has_procedure feedback mga3-64-ok Mga3 32 testing complete So the problem is mga2 rather than 32bit Whiteboard:
MGA2TOO has_procedure feedback mga3-64-ok =>
MGA2TOO has_procedure feedback mga3-64-ok mga3-32-ok Well that's ironic. mga3 is where I had to put my programmer hat on for a bit. The RedHat patches I used were for an even older qemu (actually about the same qemu-kvm version we had in mga1) and were just a simple rediff on mga2. The issue is with the files being world-writable however, which you showed didn't happen on mga2 before the update (which is also odd and unexpected). So perhaps the update is just fine (maybe unfortunate that the files are world-readable still, but that doesn't sound like what this update was supposed to address), but it takes something else to trigger the issue? Maybe for mga2 you have to enable the UNIX domain socket transport (not the default behavior) to have the issue.
David Walser
2013-06-06 14:37:25 CEST
Whiteboard:
MGA2TOO has_procedure feedback mga3-64-ok mga3-32-ok =>
MGA2TOO has_procedure mga3-64-ok mga3-32-ok Thanks David, adding mga2 32 tested in that case. Whiteboard:
MGA2TOO has_procedure mga3-64-ok mga3-32-ok =>
MGA2TOO has_procedure mga3-64-ok mga3-32-ok mga2-32-ok mga2 64 tested ok Validating Advisory & srpms in comment 0 Could sysadmin please push from 2 & 3 core/updates_testing to core/updates Thanks! Keywords:
(none) =>
validated_update http://advisories.mageia.org/MGASA-2013-0169.html Status:
NEW =>
RESOLVED
Nicolas Vigier
2014-05-08 18:06:06 CEST
CC:
boklm =>
(none) |