| Summary: | libvirt new security issues CVE-2013-4296 and CVE-2013-5651 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | davidwhodgins, mageia, oe, sysadmin-bugs, tmb |
| Version: | 3 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | i586 | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/567522/ | ||
| Whiteboard: | MGA2TOO has_procedure mga2-64-ok mga3-32-ok mga3-64-ok mga2-32-ok | ||
| Source RPM: | libvirt-1.0.2-8.1.mga3.src.rpm | CVE: | |
| Status comment: | |||
| Bug Depends on: | 11260 | ||
| Bug Blocks: | |||
|
Description
David Walser
2013-09-23 16:10:52 CEST
David Walser
2013-09-23 16:11:11 CEST
CC:
(none) =>
mageia May I request a new release of libvirt with the changes added here: http://svnweb.mageia.org/packages?view=revision&revision=484822 It makes it so much easier to use. Additionally one could also add libssh2 support by adding: BuildRequires: libssh2-devel CC:
(none) =>
oe @oden, Feel free to just bump the subrel and resubmit to testing. That said, are all these build deps also listed as runtime deps? Or are they not strictly needed at runtime? Also, IMO it's nicer to have the separate BRs on one line each as this makes contextual diffs much easier to read, but that is arguably going to spark a bikeshed debate so I'll not make any requests about this (and it's not my package anyway!!) Oden are you intending to do this or shall we proceed with the current build? If not then testing complete mga3 64 Whiteboard:
MGA2TOO =>
MGA2TOO mga3-64-ok? I will submit as of http://svnweb.mageia.org/packages?view=revision&revision=484822 but I'm not that confident with this enough to tell what's needed or not at runtime as of the question by Colin. I will also add "BuildRequires: libssh2-devel" which adds this support. Packages has been submitted to mga3 updates_testing, libvirt-1.0.2-8.4.mga3 Did you forget the ssh? No. $ rpm -qp --requires /mnt/BIG/mirror/mageia/mga3/SRPMS/core/updates_testing/libvirt-1.0.2-8.4.mga3.src.rpm | grep ssh libssh2-devel Ahh yep. That was strange, is there a delay on svnweb or was I just looking in the wrong place? What is the purpose of adding this Oden? Could you update the advisory please. http://libvirt.org/remote.html "libssh2 Transport over the SSH protocol using libssh2 instead of the OpenSSH binary. This transport uses the libvirt authentication callback for all ssh authentication calls and therefore supports keyboard-interactive authentication even with graphical management applications. As with the classic ssh transport netcat is required on the remote side." Noticed this support was activated when I built libvirt locally and had libssh2-devel installed, comparing symbols and verifying the http://svnweb.mageia.org/packages?view=revision&revision=484822 change. Testing complete mga2 64 Whiteboard:
MGA2TOO mga3-64-ok? =>
MGA2TOO mga2-64-ok I'm having difficulties with this mga2 32 in vbox lxde. Can somebody else test please. I can get it to work with vnc but not spice. It could be some oddity of trying to run it in lxde in vbox so if you're better able to test, please do :) Procedure in bug 10987 comment 6 and 7 testing complete mga3 32 Whiteboard:
MGA2TOO mga2-64-ok =>
MGA2TOO has_procedure mga2-64-ok mga3-32-ok Testing complete mga3 64 Whiteboard:
MGA2TOO has_procedure mga2-64-ok mga3-32-ok =>
MGA2TOO has_procedure mga2-64-ok mga3-32-ok mga3-64-ok I'm surprised. I actually got virt-viewer and qemu to run under vb. It's dead slow, but got far enough to confirm virt-viewer is working. Testing complete mageia 2 i586. Advisory committed to svn. Someone from the sysadmin team please push 11274.adv to updates. Keywords:
(none) =>
validated_update Update pushed: http://advisories.mageia.org/MGASA-2013-0294.html Status:
NEW =>
RESOLVED |