Re: libvirt / CVE-2019-3886

2019-04-29 Thread Brian May
Moritz Mühlenhoff writes: > We're tracking at as it's currently assigned by MITRE and it's their usual > practice to split out secondary angles to a separate CVE ID. As such, you > should rather reach out to them via https://cveform.mitre.org and request > a separate ID for the part that affects

Re: libvirt / CVE-2019-3886

2019-04-15 Thread Brian May
Moritz Mühlenhoff writes: > We're tracking at as it's currently assigned by MITRE and it's their usual > practice to split out secondary angles to a separate CVE ID. As such, you > should rather reach out to them via https://cveform.mitre.org and request > a separate ID for the part that affects

Re: libvirt / CVE-2019-3886

2019-04-11 Thread Moritz Mühlenhoff
On Tue, Apr 09, 2019 at 05:16:47PM +1000, Brian May wrote: > Guido Günther writes: > > > I don't think this is needed for jessie since the corresponding function > > in qemu was implemented in 4.8.0. > > Sounds like it won't hurt to leave this in, in any case... > > > qemuDomainGetTime is

Re: libvirt / CVE-2019-3886

2019-04-09 Thread Brian May
Brian May writes: > Ok, so it does sound like I should make this change too. Updated patch attached. -- Brian May diff -Nru libvirt-1.2.9/debian/changelog libvirt-1.2.9/debian/changelog --- libvirt-1.2.9/debian/changelog 2018-03-13 06:51:52.0 +1100 +++ libvirt-1.2.9/debian/changelog

Re: libvirt / CVE-2019-3886

2019-04-09 Thread Brian May
Guido Günther writes: > I don't think this is needed for jessie since the corresponding function > in qemu was implemented in 4.8.0. Sounds like it won't hurt to leave this in, in any case... > qemuDomainGetTime is present in 1.2.9 and uses the guest agent so it's > affected as well. The

Re: libvirt / CVE-2019-3886

2019-04-08 Thread Guido Günther
Hi, On Mon, Apr 08, 2019 at 05:50:46PM +1000, Brian May wrote: > Patch for Jessie version attached. Patch is applied by hand from > https://www.redhat.com/archives/libvir-list/2019-April/msg00339.html I don't think this is needed for jessie since the corresponding function in qemu was implemented