Bug 857490 (CVE-2013-6456) - VUL-0: CVE-2013-6456: libvirtd: unsafe usage of paths under /proc/$PID/root
Summary: VUL-0: CVE-2013-6456: libvirtd: unsafe usage of paths under /proc/$PID/root
Status: RESOLVED FIXED
Alias: CVE-2013-6456
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp3:57224
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-06 08:40 UTC by Sebastian Krahmer
Modified: 2014-06-12 17:04 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2014-01-06 23:00:21 UTC
bugbot adjusting priority
Comment 2 Sebastian Krahmer 2014-01-29 10:06:24 UTC
Is this also something that only needs openSUSE updates?
Comment 3 James Fehlig 2014-01-29 15:26:48 UTC
This issue affects libvirt 1.0.1 through 1.2.1 inclusive, meaning openSUSE13.1, Factory, SLES11 SP3, and SLE12.  In fact, the issue still exists in libvirt git master - there is no solution yet afaict.
Comment 4 James Fehlig 2014-01-29 15:28:42 UTC
I should mention, we don't support libvirt-lxc on SLE11, so fixing this in SP3 is not that urgent IMO.
Comment 7 James Fehlig 2014-03-03 04:43:51 UTC
Fixed in SLE12 beta2 (SR#33711) and Factory (SR#224371) via update to libvirt 1.2.2 release.  I believe the only thing left to do is backport the patches to 13.1.
Comment 9 Bernhard Wiedemann 2014-03-03 06:00:10 UTC
This is an autogenerated message for OBS integration:
This bug (857490) was mentioned in
https://build.opensuse.org/request/show/224371 Factory / libvirt
Comment 10 Cédric Bosdonnat 2014-03-04 19:28:58 UTC
Backported in Devel:Virt:SLE-11-SP3/libvirt and  Virtualization:openSUSE13.1/libvirt.
Comment 11 James Fehlig 2014-03-04 22:03:49 UTC
security-team: A libvirt update was recently released for SLE11 SP3, so it is not clear if we want to do another one right away.  Should this just be queued for a future maintenance cycle?
Comment 12 Bernhard Wiedemann 2014-03-21 19:00:24 UTC
This is an autogenerated message for OBS integration:
This bug (857490) was mentioned in
https://build.opensuse.org/request/show/227061 13.1 / libvirt
Comment 13 Marcus Meissner 2014-03-24 08:37:30 UTC
no immediate action, but please include in next one.
Comment 14 SMASH SMASH 2014-03-24 08:40:11 UTC
Affected packages:

SLE-11-SP3: libvirt
Comment 16 Swamp Workflow Management 2014-05-02 13:04:44 UTC
openSUSE-SU-2014:0593-1: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 852005,857490,868943,871154,873103
CVE References: CVE-2013-6456,CVE-2013-7336
Sources used:
openSUSE 13.1 (src):    libvirt-1.1.2-2.26.1
Comment 19 Cédric Bosdonnat 2014-05-12 08:14:10 UTC
This is now fixed
Comment 20 Swamp Workflow Management 2014-06-12 13:51:13 UTC
Update released for: libvirt, libvirt-client, libvirt-client-32bit, libvirt-client-64bit, libvirt-client-x86, libvirt-debuginfo, libvirt-debugsource, libvirt-devel, libvirt-devel-32bit, libvirt-devel-64bit, libvirt-doc, libvirt-lock-sanlock, libvirt-python
Products:
SLE-DEBUGINFO 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP3 (i386, x86_64)
SLE-SDK 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
Comment 21 Swamp Workflow Management 2014-06-12 17:04:24 UTC
SUSE-SU-2014:0785-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 857490,873705
CVE References: CVE-2013-6456,CVE-2014-0179
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    libvirt-1.0.5.9-0.9.1
SUSE Linux Enterprise Server 11 SP3 (src):    libvirt-1.0.5.9-0.9.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    libvirt-1.0.5.9-0.9.1