File _patchinfo of Package patchinfo.5678
<patchinfo incident="5678">
<issue id="1052151" tracker="bnc">L3: libvirt-client: broken symlink /usr/share/libvirt/libvirtLogo.png</issue>
<issue id="1031056" tracker="bnc">[pvusb][libvirt] virsh create failed with a xml with usb.</issue>
<issue id="1017189" tracker="bnc">libvirt: vbox:///session: internal error: unable to initialize VirtualBox driver API</issue>
<issue id="1012143" tracker="bnc">Unabled to create Pool storage with type=disk</issue>
<issue id="1051017" tracker="bnc">virt-manager: Error restoring domain: unsupported configuration: Unable to find security driver for model apparmor</issue>
<issue id="1049505" tracker="bnc">libvirt fails to start a VM with <seclabel type='none' model='apparmor'/> when apparmor is inactive</issue>
<issue id="1048783" tracker="bnc">libvirt-guests does not suspend all guests</issue>
<issue id="1053600" tracker="bnc">VUL-1: libvirt: ssh command injection</issue>
<issue id="1036785" tracker="bnc">Xen HVM guest unable to be started or restored with cdrom attached</issue>
<category>security</category>
<rating>moderate</rating>
<packager>jfehlig</packager>
<description>This update for libvirt fixes several issues.
This security issue was fixed:
- bsc#1053600: Escape ssh commed line to prevent interpreting malicious
hostname as arguments, allowing for command execution
These non-security issues were fixed:
- bsc#1049505, bsc#1051017: Security manager: Don't autogenerate seclabels of
type 'none' when AppArmor is inactive
- bsc#1052151: Moved /usr/share/libvirt/libvirtLogo.png symlink from client to
doc subpackage, where its target resides
- bsc#1048783: Ignore newlines in libvirt-guests.sh guest list
- bsc#1031056: Add default controllers for USB devices
- bsc#1012143: Define path to parted using autoconf cache variable. parted is
used for management of disk-based storage pools
- bsc#1036785: Prevent output of null target in domxml-to-native
</description>
<summary>Security update for libvirt</summary>
</patchinfo>