First published: Thu Jun 20 2019(Updated: )
The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems.<br>Security Fix(es):<br><li> libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API (CVE-2019-10161)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libvirt | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt-client | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt-client | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt-debuginfo | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt-debuginfo | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt-devel | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt-devel | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt-lock-sanlock | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt-python | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
redhat/libvirt-python | <0.10.2-64.el6_10.2 | 0.10.2-64.el6_10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2019:1578 is classified as moderate.
To fix RHSA-2019:1578, update the affected libvirt packages to version 0.10.2-64.el6_10.2 or later.
The affected packages include libvirt, libvirt-client, libvirt-debuginfo, libvirt-devel, and some additional libvirt-related packages.
The vulnerability in RHSA-2019:1578 allows for arbitrary file read and execution, which can pose serious security risks.
RHSA-2019:1578 was released to address security vulnerabilities in the libvirt library.