File _patchinfo of Package patchinfo.7322

<patchinfo incident="7322">
  <issue id="1051017" tracker="bnc">virt-manager: Error restoring domain: unsupported configuration: Unable to find security driver for model apparmor</issue>
  <issue id="1053600" tracker="bnc">VUL-1: libvirt: ssh command injection</issue>
  <issue id="1049505" tracker="bnc">libvirt fails to start a VM with &lt;seclabel type='none' model='apparmor'/&gt; when apparmor is inactive</issue>
  <issue id="1045693" tracker="bnc">libvirt Backport for potential incompatibility with OpenStack Pike</issue>
  <category>security</category>
  <rating>moderate</rating>
  <packager>jfehlig</packager>
  <description>This update for libvirt fixes several issues.

This security issue was fixed:

- bsc#1053600: Escape ssh commed line to prevent interpreting malicious
  hostname as arguments, allowing for command execution

These non-security issues were fixed:

- bsc#1049505, bsc#1051017: Security manager: Don't autogenerate seclabels of
  type 'none' when AppArmor is inactive
- bsc#1045693: Support chardevs with ARM machines 

This update was imported from the SUSE:SLE-12-SP3:Update update project.</description>
  <summary>Security update for libvirt</summary>
</patchinfo>
openSUSE Build Service is sponsored by