DSA-4003-1 libvirt -- security update

Related Vulnerabilities: CVE-2017-1000256  

Daniel P. Berrange reported that Libvirt, a virtualisation abstraction library, does not properly handle the default_tls_x509_verify (and related) parameters in qemu.conf when setting up TLS clients and servers in QEMU, resulting in TLS clients for character devices and disk devices having verification turned off and ignoring any errors while validating the server certificate. More informations in https://security.libvirt.org/2017/0002.html . For the stable distribution (stretch), this problem has been fixed in version 3.0.0-4+deb9u1. For the unstable distribution (sid), this problem has been fixed in version 3.8.0-3. We recommend that you upgrade your libvirt packages.

Debian Security Advisory

DSA-4003-1 libvirt -- security update

Date Reported:
19 Oct 2017
Affected Packages:
libvirt
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 878799.
In Mitre's CVE dictionary: CVE-2017-1000256.
More information:

Daniel P. Berrange reported that Libvirt, a virtualisation abstraction library, does not properly handle the default_tls_x509_verify (and related) parameters in qemu.conf when setting up TLS clients and servers in QEMU, resulting in TLS clients for character devices and disk devices having verification turned off and ignoring any errors while validating the server certificate.

More informations in https://security.libvirt.org/2017/0002.html .

For the stable distribution (stretch), this problem has been fixed in version 3.0.0-4+deb9u1.

For the unstable distribution (sid), this problem has been fixed in version 3.8.0-3.

We recommend that you upgrade your libvirt packages.