Advisories ยป MGASA-2013-0166

Updated libvirt packages fix security vulnerability

Publication date: 06 Jun 2013
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-1962

Description

It was found that libvirtd leaked file descriptors when listing all volumes
for a particular pool. A remote attacker able to establish a read-only
connection to libvirtd could use this flaw to cause libvirtd to consume all
available file descriptors, preventing other users from using libvirtd
services (such as starting a new guest) until libvirtd is restarted
(CVE-2013-1962).
                

References

SRPMS

3/core