-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 14 Mar 2011 21:33:33 +0100 Source: libvirt Binary: libvirt-bin libvirt0 libvirt0-dbg libvirt-doc libvirt-dev python-libvirt Architecture: sparc Version: 0.8.3-5+squeeze1 Distribution: squeeze-security Urgency: low Maintainer: sparc Build Daemon (schroeder) Changed-By: Guido Günther Description: libvirt-bin - the programs for the libvirt library libvirt-dev - development files for the libvirt library libvirt-doc - documentation for the libvirt library libvirt0 - library for interfacing with different virtualization systems libvirt0-dbg - library for interfacing with different virtualization systems python-libvirt - libvirt Python bindings Closes: 617773 Changes: libvirt (0.8.3-5+squeeze1) stable-security; urgency=low . * [0ee351f] [CVE-2011-1146] Add missing checks for read only connections. Some API forgot to check the read-only status of the connection for entry point which modify the state of the system or may lead to a remote execution using user data. The entry points concerned are: - virConnectDomainXMLToNative - virNodeDeviceDettach - virNodeDeviceReAttach - virNodeDeviceReset - virDomainRevertToSnapshot - virDomainSnapshotDelete src/libvirt.c: fix the above set of entry points to error on read-only (Closes: #617773) Checksums-Sha1: 049c16b1d005926e86e03d7766ac6724acb8b918 1040178 libvirt-bin_0.8.3-5+squeeze1_sparc.deb 2a2fcb2d59ee1c0f92eeb6b96ec22d325b5a937f 755808 libvirt0_0.8.3-5+squeeze1_sparc.deb 08acee6d60c2d8a3bf2d2597bc3539a515ecdbe1 2428492 libvirt0-dbg_0.8.3-5+squeeze1_sparc.deb 5a8a9daa8498ea447886b8fa86d7cdae8bbd318a 930902 libvirt-dev_0.8.3-5+squeeze1_sparc.deb 7cfe965101cae3e03a89217a2ca5d7c53b534173 442040 python-libvirt_0.8.3-5+squeeze1_sparc.deb Checksums-Sha256: 8f31e464da7aa872d2bc911259269f551afd547f8f270fa143364cae6202aeab 1040178 libvirt-bin_0.8.3-5+squeeze1_sparc.deb 91a7358782e751611d1a33d6bd585a888491dc04391fceab97b1b9420a1c5b15 755808 libvirt0_0.8.3-5+squeeze1_sparc.deb 7348b8bc4ab59608d79f0ed3c6012a8849599690f88ae4313a9a83551e81bb7f 2428492 libvirt0-dbg_0.8.3-5+squeeze1_sparc.deb db452b73774a263a0633742ada36086f80bcdab9052fb54daf62b15c5d529198 930902 libvirt-dev_0.8.3-5+squeeze1_sparc.deb 62c3eb4fd9dfe5ea540e5f5a86dc220a0bb56e9a2f040fc9a8375558a6e6ada9 442040 python-libvirt_0.8.3-5+squeeze1_sparc.deb Files: 07daae11e4e7ce33477741262fff0a6e 1040178 admin optional libvirt-bin_0.8.3-5+squeeze1_sparc.deb 6883f88d05e564aa4336041b9f86ad6b 755808 libs optional libvirt0_0.8.3-5+squeeze1_sparc.deb e2bd71702469606f10a4f123c6e9e552 2428492 debug extra libvirt0-dbg_0.8.3-5+squeeze1_sparc.deb bf657fde6a3b8f33c1073fdf5f8482f1 930902 libdevel optional libvirt-dev_0.8.3-5+squeeze1_sparc.deb 176df09db7f23d11d4f07baf28700be4 442040 python optional python-libvirt_0.8.3-5+squeeze1_sparc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJNgwXIAAoJEOxfUAG2iX57n2gIAKPUGETmP3HuurVbjmTQH5cG 9yoK5Kdw70Yw5LLwBiHWg019ad7NEtl+YWM5TxVmDwgnCH5vOKP8sm/+zkRCmogA a4Na4u3VHvx7Ni7pkbt/h7yREqV1iwm6MZ5K9CcA0uRQtkTyb8mKepUPwKKZxr7k epHaOmrIWuSWBoaeZ97Z9E9spn4mvqWdiretLkKD+2jzurpI0o4wdeVO2FXn+diK +3WFcPySkIByHdvjrROEXBqMkZX1+10ChiSEX0ZlZ7JSeo70THA50iCT1dZTbCXJ QIfBprpJ3B2T49oy96ThWy9He9jPDUdJ4PedFn8ifSy0Ua0RBsTMKJ1RQmijcMI= =ahPD -----END PGP SIGNATURE-----