-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 14 Mar 2011 21:33:33 +0100 Source: libvirt Binary: libvirt-bin libvirt0 libvirt0-dbg libvirt-doc libvirt-dev python-libvirt Architecture: ia64 Version: 0.8.3-5+squeeze1 Distribution: squeeze-security Urgency: low Maintainer: ia64 Build Daemon (mundy) Changed-By: Guido Günther Description: libvirt-bin - the programs for the libvirt library libvirt-dev - development files for the libvirt library libvirt-doc - documentation for the libvirt library libvirt0 - library for interfacing with different virtualization systems libvirt0-dbg - library for interfacing with different virtualization systems python-libvirt - libvirt Python bindings Closes: 617773 Changes: libvirt (0.8.3-5+squeeze1) stable-security; urgency=low . * [0ee351f] [CVE-2011-1146] Add missing checks for read only connections. Some API forgot to check the read-only status of the connection for entry point which modify the state of the system or may lead to a remote execution using user data. The entry points concerned are: - virConnectDomainXMLToNative - virNodeDeviceDettach - virNodeDeviceReAttach - virNodeDeviceReset - virDomainRevertToSnapshot - virDomainSnapshotDelete src/libvirt.c: fix the above set of entry points to error on read-only (Closes: #617773) Checksums-Sha1: 1810a343e93f7dda113a3761672704f28f24005a 1067298 libvirt-bin_0.8.3-5+squeeze1_ia64.deb 0ca9ab2d1328a9c52fa5a8605039ff773913a138 883156 libvirt0_0.8.3-5+squeeze1_ia64.deb b15114e9ea70cbbd1b7b80c2319aeac25e3bccad 2171422 libvirt0-dbg_0.8.3-5+squeeze1_ia64.deb c74af2df449bee8cea093e7713c0b6201e5f07f9 1097156 libvirt-dev_0.8.3-5+squeeze1_ia64.deb d5991e2d84a76409b284fa6033e1ff2038ae6af6 453096 python-libvirt_0.8.3-5+squeeze1_ia64.deb Checksums-Sha256: c5a6e7aade92d86f19242fc97f09ee14a07fb23b6c369cc549298dfa4930dae8 1067298 libvirt-bin_0.8.3-5+squeeze1_ia64.deb 2f70e386f038ff029026f22e8a346f8aa637034c1d46101356272a772207b9ab 883156 libvirt0_0.8.3-5+squeeze1_ia64.deb ca61d99b7bb4340661a18aab7774c9fd45e94b53c9f79f1f27cd0d6a690c6440 2171422 libvirt0-dbg_0.8.3-5+squeeze1_ia64.deb e06d7807dc10dd507a623dbd2a20966876055ca1941ab791d075d584ee61c44d 1097156 libvirt-dev_0.8.3-5+squeeze1_ia64.deb fe9ce0c6733d30efea3c4d7169318359ae4b5468ac67616e4d58612cc0229e3f 453096 python-libvirt_0.8.3-5+squeeze1_ia64.deb Files: 4aa05c30f9ce9dd0cc36e20af212f118 1067298 admin optional libvirt-bin_0.8.3-5+squeeze1_ia64.deb 7f2ace9b1c2a52220266a271d9d22b83 883156 libs optional libvirt0_0.8.3-5+squeeze1_ia64.deb a597a2c836283b58f478d1fbdb671d7a 2171422 debug extra libvirt0-dbg_0.8.3-5+squeeze1_ia64.deb 08aed9217deaf46d47ab2526763be0e1 1097156 libdevel optional libvirt-dev_0.8.3-5+squeeze1_ia64.deb c9886347c4093508207fb1ecb5d84434 453096 python optional python-libvirt_0.8.3-5+squeeze1_ia64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJNgwXIAAoJEOxfUAG2iX5733MH/3xvl8dGgQNrl1Mo3VwyAC+L 6Bp9blRQqoCSRWY2RR+PjjWDzTR5NGJvSpWFJZiU6IsJi6dEiAX+OkFa//vtyJBF 4KA4r8lrC5CrVy8OYet/jONMclSDhBRDWid0ZI25xcLUHgFfPIT2BC73+CNHdWqF OIh+40H4WOScrVZgrXLkBl1Xds8n9jdhYSr+JhZ9Tse8B/knNJKMdT/f1sKFEQKz n3xmONcW0dlnLdQ/mPCHmKiyOmKY1w9WWH7NOdK0tF6Vv/EWQJiXSB1HJcI4xZ4p 0FLxhbet+/W0g05/EcFz1GGslDWjCPuZ8qhg7DF/+2id2iP/lk+ZmKw3QTKLDPQ= =Nqn9 -----END PGP SIGNATURE-----