First published: Mon Jan 13 2020(Updated: )
USN-4047-1 fixed a vulnerability in libvirt. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Matthias Gerstner and Ján Tomko discovered that libvirt incorrectly handled certain API calls. An attacker could possibly use this issue to check for arbitrary files, or execute arbitrary binaries. In the default installation, attackers would be isolated by the libvirt AppArmor profile.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libvirt0 | <1.2.2-0ubuntu13.1.28+esm1 | 1.2.2-0ubuntu13.1.28+esm1 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/libvirt-bin | <1.2.2-0ubuntu13.1.28+esm1 | 1.2.2-0ubuntu13.1.28+esm1 |
Ubuntu OpenSSH Client | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this update is USN-4047-2.
The affected software is libvirt version 1.2.2-0ubuntu13.1.28+esm1 on Ubuntu 14.04.
The severity of USN-4047-2 is not specified in the information provided.
To fix the vulnerability, update your libvirt package to version 1.2.2-0ubuntu13.1.28+esm1 or later.
You can find more information about USN-4047-2 on the Ubuntu Security website.