RHSA-2013:1181: Moderate: rhev-hypervisor6 security and bug fix update
The rhev-hypervisor6 package provides a Red Hat Enterprise VirtualizationHypervisor ISO disk image. The Red Hat Enterprise Virtualization Hypervisoris a dedicated Kernel-based Virtual Machine (KVM) hypervisor. It includeseverything necessary to run and manage virtual machines: A subset of theRed Hat Enterprise Linux operating environment and the Red Hat EnterpriseVirtualization Agent.Note: Red Hat Enterprise Virtualization Hypervisor is only available forthe Intel 64 and AMD64 architectures with virtualization extensions.Upgrade Note: If you upgrade the Red Hat Enterprise VirtualizationHypervisor through the 3.2 Manager administration portal, the Host mayappear with the status of "Install Failed". If this happens, place the hostinto maintenance mode, then activate it again to get the host back to an"Up" state.It was discovered that NSS leaked timing information when decryptingTLS/SSL and DTLS protocol encrypted records when CBC-mode cipher suiteswere used. A remote attacker could possibly use this flaw to retrieve plaintext from the encrypted packets by using a TLS/SSL or DTLS server as apadding oracle. (CVE-2013-1620)It was found that the fix for CVE-2013-0167 released via RHSA-2013:0907was incomplete. A privileged guest user could potentially use this flaw tomake the host the guest is running on unavailable to the managementserver. (CVE-2013-4236)An out-of-bounds memory read flaw was found in the way NSS decoded certaincertificates. If an application using NSS decoded a malformed certificate,it could cause the application to crash. (CVE-2013-0791)Red Hat would like to thank the Mozilla project for reportingCVE-2013-0791. Upstream acknowledges Ambroz Bizjak as the original reporterof CVE-2013-0791. The CVE-2013-4236 issue was found by David Gibson of RedHat.This updated package provides updated components that include fixes forvarious security issues. These issues have no security impact on Red HatEnterprise Virtualization Hypervisor itself, however. The security fixesincluded in this update address the following CVE numbers:CVE-2013-4854 (bind issue)CVE-2012-6544, CVE-2013-2146, CVE-2013-2206, CVE-2013-2224, CVE-2013-2232,and CVE-2013-2237 (kernel issues)This update also contains the fixes from the following errata: vdsm: RHSA-2013:1155 and RHBA-2013:1158 Users of the Red Hat Enterprise Virtualization Hypervisor are advised toupgrade to this updated package, which corrects these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2013:1181?
The severity of RHSA-2013:1181 is classified as important.
What does RHSA-2013:1181 address?
RHSA-2013:1181 addresses vulnerabilities in the rhev-hypervisor6 package which provides the Red Hat Enterprise Virtualization Hypervisor.
How do I fix RHSA-2013:1181?
To fix RHSA-2013:1181, you should upgrade the rhev-hypervisor6 package to version 6.4-20130815.0.el6_4.
Which systems are affected by RHSA-2013:1181?
RHSA-2013:1181 affects systems running the rhev-hypervisor6 package prior to version 6.4-20130815.0.el6_4.
Is there a known exploit for RHSA-2013:1181?
Yes, there are known exploits that target vulnerabilities addressed by RHSA-2013:1181.