Bugzilla – Full Text Bug Listing |
Summary: | VUL-1: CVE-2018-6764: libvirt: guest could inject executable code via libnss_dns.so loaded by libvirt_lxc before init | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Johannes Segitz <jsegitz> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Minor | ||
Priority: | P4 - Low | CC: | atoptsoglou, cbosdonnat, smash_bz |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/199648/ | ||
Whiteboard: | CVSSv3:SUSE:CVE-2018-6764:6.8:(AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L) | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Johannes Segitz
2018-02-08 11:13:27 UTC
libvirt-lxc is mine Fix stacked for the next maintenance update for 12-SP2 and 12-SP3. The libvirt LXC driver is not supported on SLE 11, thus I haven't backported the patch to this version. Fix will be submitted to factory and SLE-15 soon. This is an autogenerated message for OBS integration: This bug (1080042) was mentioned in https://build.opensuse.org/request/show/574875 Factory / libvirt This is an autogenerated message for OBS integration: This bug (1080042) was mentioned in https://build.opensuse.org/request/show/575802 Factory / libvirt SUSE-SU-2018:0861-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1078808,1079869,1080042,1082041,1083625 CVE References: CVE-2017-5715,CVE-2018-1064,CVE-2018-6764 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP2 (src): libvirt-2.0.0-27.34.1 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): libvirt-2.0.0-27.34.1 SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src): libvirt-2.0.0-27.34.1 SUSE Linux Enterprise Server 12-SP2 (src): libvirt-2.0.0-27.34.1 SUSE Linux Enterprise Desktop 12-SP2 (src): libvirt-2.0.0-27.34.1 SUSE-SU-2018:0920-1: An update that solves three vulnerabilities and has 7 fixes is now available. Category: security (important) Bug References: 1054986,1067018,1070615,1079869,1080042,1082041,1082161,1083625,1085757,1086038 CVE References: CVE-2017-5715,CVE-2018-1064,CVE-2018-6764 Sources used: SUSE Linux Enterprise Software Development Kit 12-SP3 (src): libvirt-3.3.0-5.19.2 SUSE Linux Enterprise Server 12-SP3 (src): libvirt-3.3.0-5.19.2, virt-manager-1.4.1-5.8.1 SUSE Linux Enterprise Desktop 12-SP3 (src): libvirt-3.3.0-5.19.2, virt-manager-1.4.1-5.8.1 openSUSE-SU-2018:0939-1: An update that solves three vulnerabilities and has 7 fixes is now available. Category: security (important) Bug References: 1054986,1067018,1070615,1079869,1080042,1082041,1082161,1083625,1085757,1086038 CVE References: CVE-2017-5715,CVE-2018-1064,CVE-2018-6764 Sources used: openSUSE Leap 42.3 (src): libvirt-3.3.0-15.1, virt-manager-1.4.1-9.1 back to security team... fixed a long time ago Done |