• libvirt vulnerability

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Tuesday, August 04, 2020 16:10:06
    libvirt vulnerability

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS

    Summary

    libvirt could be made to run programs as an administrator.

    Software Description

    * libvirt - Libvirt virtualization toolkit

    Details

    Trent Shea discovered that the libvirt package set incorrect
    permissions on the UNIX domain socket. A local attacker could use
    this issue to access libvirt and escalate privileges.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    libvirt-daemon - 6.0.0-0ubuntu8.3
    libvirt-daemon-system - 6.0.0-0ubuntu8.3
    libvirt0 - 6.0.0-0ubuntu8.3

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    After a standard system update you need to reboot your computer to
    make all the necessary changes.

    References

    * CVE-2020-15708

    --- Mystic BBS v1.12 A46 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)