Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.881583
Categoría:CentOS Local Security Checks
Título:CentOS Update for libvirt CESA-2013:0199 centos6
Resumen:The remote host is missing an update for the 'libvirt'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'libvirt'
package(s) announced via the referenced advisory.

Vulnerability Insight:
The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In
addition, libvirt provides tools for remote management of virtualized
systems.

A flaw was found in the way libvirtd handled connection cleanup (when a
connection was being closed) under certain error conditions. A remote
attacker able to establish a read-only connection to libvirtd could use
this flaw to crash libvirtd or, potentially, execute arbitrary code with
the privileges of the root user. (CVE-2013-0170)

This issue was discovered by Tingting Zheng of Red Hat.

All users of libvirt are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
the updated packages, libvirtd will be restarted automatically.

Affected Software/OS:
libvirt on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2013-0170
BugTraq ID: 57578
http://www.securityfocus.com/bid/57578
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098398.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098370.html
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098326.html
http://osvdb.org/89644
RedHat Security Advisories: RHSA-2013:0199
http://rhn.redhat.com/errata/RHSA-2013-0199.html
http://www.securitytracker.com/id/1028047
http://secunia.com/advisories/52001
http://secunia.com/advisories/52003
SuSE Security Announcement: SUSE-SU-2013:0320 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00016.html
SuSE Security Announcement: openSUSE-SU-2013:0274 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00001.html
SuSE Security Announcement: openSUSE-SU-2013:0275 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00002.html
http://www.ubuntu.com/usn/USN-1708-1
XForce ISS Database: libvirt-virnetmessagefree-code-exec(81552)
https://exchange.xforce.ibmcloud.com/vulnerabilities/81552
CopyrightCopyright (C) 2013 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.