-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-18300 2013-10-05 01:22:43 --------------------------------------------------------------------------------
Name : xen Product : Fedora 20 Version : 4.3.0 Release : 7.fc20 URL : http://xen.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: Three security fixes CVE-2013-4355 CVE-2013-4356 CVE-2013-4361, Set "Domain-0" label in xenstored.service systemd file -------------------------------------------------------------------------------- References: [ 1 ] Bug #1009598 - CVE-2013-4355 Kernel: Xen: Xsa-63: information leak via I/O instruction emulation https://bugzilla.redhat.com/show_bug.cgi?id=1009598 [ 2 ] Bug #1009553 - CVE-2013-4356 Kernel: Xen: Xsa-64: memory leak by 64bit PV guests under live migration https://bugzilla.redhat.com/show_bug.cgi?id=1009553 [ 3 ] Bug #1009817 - CVE-2013-4361 Kernel: Xen: Xsa-66: information leak through fbld instruction emulation https://bugzilla.redhat.com/show_bug.cgi?id=1009817 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update xen' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
