-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 14 Mar 2011 21:33:33 +0100 Source: libvirt Binary: libvirt-bin libvirt0 libvirt0-dbg libvirt-doc libvirt-dev python-libvirt Architecture: armel Version: 0.8.3-5+squeeze1 Distribution: squeeze-security Urgency: low Maintainer: armel Build Daemon (alain) Changed-By: Guido Günther Description: libvirt-bin - the programs for the libvirt library libvirt-dev - development files for the libvirt library libvirt-doc - documentation for the libvirt library libvirt0 - library for interfacing with different virtualization systems libvirt0-dbg - library for interfacing with different virtualization systems python-libvirt - libvirt Python bindings Closes: 617773 Changes: libvirt (0.8.3-5+squeeze1) stable-security; urgency=low . * [0ee351f] [CVE-2011-1146] Add missing checks for read only connections. Some API forgot to check the read-only status of the connection for entry point which modify the state of the system or may lead to a remote execution using user data. The entry points concerned are: - virConnectDomainXMLToNative - virNodeDeviceDettach - virNodeDeviceReAttach - virNodeDeviceReset - virDomainRevertToSnapshot - virDomainSnapshotDelete src/libvirt.c: fix the above set of entry points to error on read-only (Closes: #617773) Checksums-Sha1: a8afc5fb7a032746d780a6d54e615f7b7225b7da 1041808 libvirt-bin_0.8.3-5+squeeze1_armel.deb a04f2c2b03a8a3841ef0ba068a9902d852fe824b 743632 libvirt0_0.8.3-5+squeeze1_armel.deb 5a322520053bee4179d012cb79e8e931b2cfaa13 2558992 libvirt0-dbg_0.8.3-5+squeeze1_armel.deb 6f4c0f31737a75f2ea2c024882646afe2d7e033c 900170 libvirt-dev_0.8.3-5+squeeze1_armel.deb ffef4559ebac04856d77aa5e8938b22be1f8ad13 435600 python-libvirt_0.8.3-5+squeeze1_armel.deb Checksums-Sha256: 58a6029d4667423329d50c7147b1443b342cab3364deac043cf8c3780796bf6b 1041808 libvirt-bin_0.8.3-5+squeeze1_armel.deb d23734e36efe304f1d9c6025cf906bfbe7037484bf6fefe6411bdc64de7daa02 743632 libvirt0_0.8.3-5+squeeze1_armel.deb 1e9a10d3e361b4beb4d271e9af9bbca1071b30206ae91bf40a7a361493ec209e 2558992 libvirt0-dbg_0.8.3-5+squeeze1_armel.deb 142b060593ed562c01918673f5a26d50c7e5e137924b5701c84dcfbad83f8de6 900170 libvirt-dev_0.8.3-5+squeeze1_armel.deb 7839f2572894708f941b91fa12a279498d3fed7b9a01b1c592e44ecd81add852 435600 python-libvirt_0.8.3-5+squeeze1_armel.deb Files: 65b48b5587fedbc1bbcdcf223f9d3407 1041808 admin optional libvirt-bin_0.8.3-5+squeeze1_armel.deb cbce59aecd68b45685690923365c7931 743632 libs optional libvirt0_0.8.3-5+squeeze1_armel.deb 590dfc9716f774f09d45e787b8f197e2 2558992 debug extra libvirt0-dbg_0.8.3-5+squeeze1_armel.deb f4b0b89b533c5da89f01506e7fad7935 900170 libdevel optional libvirt-dev_0.8.3-5+squeeze1_armel.deb 4ae931cf493b83ce948e4424d2f05a05 435600 python optional python-libvirt_0.8.3-5+squeeze1_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJNgwXJAAoJEOxfUAG2iX572lcH/08yLD9QcC/e2uVpVYfucLj1 WOGDxwaPMIK9u13a8jBkEcNGtqRMAp3J9j9X/OVubBn0HgNWWSgXA5yBdgkDqxV6 3BYgulL5LIppGmdCm/Dib+pzbBDzWTllE+NOtUcgF3YYBIuLoa17TrE4GXaXZdnN llNEVf6UGTcMa/UdXilVX8khwzIc1ia7yCPrwZATtGTsh2Izgb2epUyDNWiCNvvN iowlAdN/DnxIzLOq2bqpQqigEPu8JnAb6xcyIROJb1QhQ4OThu/sHj/DFjO7NP73 nThsFi/EtyYE4cpi5A+tdJ3Q6gvTPdBn6kq3OjOBlviXLr7EcN/UYrpKMLxXEwc= =V4it -----END PGP SIGNATURE-----