-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 14 Mar 2011 21:33:33 +0100 Source: libvirt Binary: libvirt-bin libvirt0 libvirt0-dbg libvirt-doc libvirt-dev python-libvirt Architecture: powerpc Version: 0.8.3-5+squeeze1 Distribution: squeeze-security Urgency: low Maintainer: powerpc Build Daemon (porpora) Changed-By: Guido Günther Description: libvirt-bin - the programs for the libvirt library libvirt-dev - development files for the libvirt library libvirt-doc - documentation for the libvirt library libvirt0 - library for interfacing with different virtualization systems libvirt0-dbg - library for interfacing with different virtualization systems python-libvirt - libvirt Python bindings Closes: 617773 Changes: libvirt (0.8.3-5+squeeze1) stable-security; urgency=low . * [0ee351f] [CVE-2011-1146] Add missing checks for read only connections. Some API forgot to check the read-only status of the connection for entry point which modify the state of the system or may lead to a remote execution using user data. The entry points concerned are: - virConnectDomainXMLToNative - virNodeDeviceDettach - virNodeDeviceReAttach - virNodeDeviceReset - virDomainRevertToSnapshot - virDomainSnapshotDelete src/libvirt.c: fix the above set of entry points to error on read-only (Closes: #617773) Checksums-Sha1: 7857035affdc0f1ab49e5427301875be64c60b0f 1071912 libvirt-bin_0.8.3-5+squeeze1_powerpc.deb 916989b97d82f3279e8194ce78e69cac65507379 785644 libvirt0_0.8.3-5+squeeze1_powerpc.deb 52b6a9af0db8ceedbc28cf490de4b889dff2db45 2615910 libvirt0-dbg_0.8.3-5+squeeze1_powerpc.deb c69f8d33034455f7f48e0c63056aadc352238f74 893580 libvirt-dev_0.8.3-5+squeeze1_powerpc.deb b553ac5405ace53589695e65252436dd79837af6 444700 python-libvirt_0.8.3-5+squeeze1_powerpc.deb Checksums-Sha256: 3edacb99356dd27aa52379c3d577e8a9400789d1828958cda3413bc2ddeda9de 1071912 libvirt-bin_0.8.3-5+squeeze1_powerpc.deb 15c8a1cb629121b9002cbd6838bf6d95c7abae2b0efe9b66c2de34d91638133f 785644 libvirt0_0.8.3-5+squeeze1_powerpc.deb 019472eb8dda21c8f6b830efccd1f503e7fe3694ea37f0392613a57b1b7b6df0 2615910 libvirt0-dbg_0.8.3-5+squeeze1_powerpc.deb 61f4bbc0e3258f99d870d45de17779343b7f8a1181ed137978d2b05c725fe662 893580 libvirt-dev_0.8.3-5+squeeze1_powerpc.deb 46f1b069e949df1d58c727d23b72271d819d8e460d657310b4de683753038f83 444700 python-libvirt_0.8.3-5+squeeze1_powerpc.deb Files: b1470eb825683d503278e543d3b33ab9 1071912 admin optional libvirt-bin_0.8.3-5+squeeze1_powerpc.deb fd6a293fd12cf8d5f6c368774c870b9e 785644 libs optional libvirt0_0.8.3-5+squeeze1_powerpc.deb 3e00dc4730f127b3ea27e8933cce5e27 2615910 debug extra libvirt0-dbg_0.8.3-5+squeeze1_powerpc.deb c8f1a9a9d72469be94e83f95dc4da9d8 893580 libdevel optional libvirt-dev_0.8.3-5+squeeze1_powerpc.deb 62ebd0e410d12e8ebadc120bee9fbce0 444700 python optional python-libvirt_0.8.3-5+squeeze1_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJNgwXIAAoJEOxfUAG2iX57tDUH/0+ZVXIg/cZOx9YnU0TPj8Yz 1UNrcwCEO1NFLaPwCLjUwE1qZOT7Acwdpw1wWeVLLa8zPJDRDBR+o9lqTGuMMqr6 GHtIpTMbnoxJnPNIwmcFCZm1iVmml7VNPqxzBFr4tzFE6htZflqYwVDbLrhrge8O vWJkq8qmoW70uhPCS+gRQX6GBwl0znhw9MaFWa1Niq8L0omYLePJVhHzl22KHkYy lPWiTF6EH6GCQ1F0sEtZSJKNDbWlqfK9dzLAZB+x8L5IoELS9ISl9DGuJCDvx9Rf BNX2A+K1JKi6QQwjIfF1Z2UEWehzLV4pmlkIcIkJREuUVZOT1GKLCQdfCZY/ZoM= =v/SW -----END PGP SIGNATURE-----