Summary
Multiple security issues have been found in Libvirt, a virtualisation abstraction library:
CVE-2013-6458
It was discovered that insecure job usage could lead to denial of service against libvirtd.
CVE-2014-1447
It was discovered that a race condition in keepalive handling could lead to denial of service against libvirtd.
Solution
For the stable distribution (wheezy), these problems have been fixed in version 0.9.12.3-1. This bugfix point release also addresses some additional bugfixes.
For the unstable distribution (sid), these problems have been fixed in version 1.2.1-1.
We recommend that you upgrade your libvirt packages.
Insight
Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes).
Affected
libvirt on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2013-6458, CVE-2014-1447 -
CVSS Base Score: 6.8
AV:A/AC:H/Au:N/C:C/I:C/A:C
Related Vulnerabilities