MGASA-2020-0250

Source
https://advisories.mageia.org/MGASA-2020-0250.html
Import Source
https://advisories.mageia.org/MGASA-2020-0250.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0250
Related
Published
2020-06-10T22:26:12Z
Modified
2020-06-10T23:17:53Z
Summary
Updated libvirt packages fix security vulnerability
Details

Updated libvirt packages fix security vulnerability:

It was discovered that libvirt incorrectly handled an active pool without a target path. A remote attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service (CVE-2020-10703).

It was discovered that libvirt incorrectly handled memory when retrieving certain domain statistics. A remote attacker could possibly use this issue to cause libvirt to consume resources, resulting in a denial of service (CVE-2020-12430).

References
Credits

Affected packages

Mageia:7 / libvirt

Package

Name
libvirt
Purl
pkg:rpm/mageia/libvirt?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.5.0-1.1.mga7

Ecosystem specific

{
    "section": "core"
}