-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 14 Mar 2011 21:33:33 +0100 Source: libvirt Binary: libvirt-bin libvirt0 libvirt0-dbg libvirt-doc libvirt-dev python-libvirt Architecture: amd64 Version: 0.8.3-5+squeeze1 Distribution: squeeze-security Urgency: low Maintainer: amd64 Builddd Daemon (barber) Changed-By: Guido Günther Description: libvirt-bin - the programs for the libvirt library libvirt-dev - development files for the libvirt library libvirt-doc - documentation for the libvirt library libvirt0 - library for interfacing with different virtualization systems libvirt0-dbg - library for interfacing with different virtualization systems python-libvirt - libvirt Python bindings Closes: 617773 Changes: libvirt (0.8.3-5+squeeze1) stable-security; urgency=low . * [0ee351f] [CVE-2011-1146] Add missing checks for read only connections. Some API forgot to check the read-only status of the connection for entry point which modify the state of the system or may lead to a remote execution using user data. The entry points concerned are: - virConnectDomainXMLToNative - virNodeDeviceDettach - virNodeDeviceReAttach - virNodeDeviceReset - virDomainRevertToSnapshot - virDomainSnapshotDelete src/libvirt.c: fix the above set of entry points to error on read-only (Closes: #617773) Checksums-Sha1: fa8fd9a732ca856deb7ccca2c58ff23d665cb13f 1045252 libvirt-bin_0.8.3-5+squeeze1_amd64.deb 2d2af3c5a4f00f72c43907fc848478d1e7e5577f 977146 libvirt0_0.8.3-5+squeeze1_amd64.deb cf538e62236b9225deffd3c663205287683259c0 3152784 libvirt0-dbg_0.8.3-5+squeeze1_amd64.deb 3b9930a5c5f98f9d213208d7687e3e7776b44045 1197406 libvirt-dev_0.8.3-5+squeeze1_amd64.deb e489fa99ab5a435a156e22fda490f63581299b6d 441358 python-libvirt_0.8.3-5+squeeze1_amd64.deb Checksums-Sha256: a2b7396143a9993535207cd330ad84ea2d6248a5b95d5a1d1e7de3eefdc4405d 1045252 libvirt-bin_0.8.3-5+squeeze1_amd64.deb 9f045b40bf14ae83536f7fb1159ace952379112bfd393cdd46039f148d454f6f 977146 libvirt0_0.8.3-5+squeeze1_amd64.deb ae241a9f3e67c102093351091e01ee435e864a3f12179942b307bb89c0eb0171 3152784 libvirt0-dbg_0.8.3-5+squeeze1_amd64.deb 7e837a0fe068317581e800a95b044b0782de14600304757297ca1f5cd9b4b17f 1197406 libvirt-dev_0.8.3-5+squeeze1_amd64.deb 303720bb579b276745f46e33b8bcbb16264753a070c34f04fd6303d734acb31a 441358 python-libvirt_0.8.3-5+squeeze1_amd64.deb Files: 44acd243f83412632be6369dc0c13659 1045252 admin optional libvirt-bin_0.8.3-5+squeeze1_amd64.deb ee82e90a48342e786a10bb7bdd06da01 977146 libs optional libvirt0_0.8.3-5+squeeze1_amd64.deb c9fff180beefbdfcfba358e5487ae85c 3152784 debug extra libvirt0-dbg_0.8.3-5+squeeze1_amd64.deb 667771fb62aaf5e4e1e61ae7652447db 1197406 libdevel optional libvirt-dev_0.8.3-5+squeeze1_amd64.deb 49e261a47624b03ed4f0fab1a12b2389 441358 python optional python-libvirt_0.8.3-5+squeeze1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJNgwXIAAoJEOxfUAG2iX57lYUH/A1xNs9rNuBL+4LmxOtCGH0V DmWW4EnM1ZJfknFffY77s4vele5bEKCQzVG3OJoCt7XcRN9kAImRdLJteGKv7vt2 G4TvCyBtqUfrQZw2QY5cA9GiPNdiP2Hu9i9JmyMDTc7FO5sxcNVDfttbazw5HxM3 lJARoG7+9VgHha9UNdICOD32RJOpBn0O4pPvDV7a7dllEJvNP+doa/eQy+qothgu 85yLbBxu9GLkgs0t+eYN5jq0OqAJqWyegEko1jFaOGOUio4eSN8veKgPk15cip/t Xz9g1S6keqFqtJdcZZwd8l/eQWOuCcMJ84oG55SBg9qnQTMoH1uHH3C1V/LCKMk= =cXZh -----END PGP SIGNATURE-----