==========================================================================
Ubuntu Security Notice USN-4452-1
August 04, 2020
libvirt vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 20.04 LTS
Summary:
libvirt could be made to run programs as an administrator.
Software Description:
– libvirt: Libvirt virtualization toolkit
Details:
Trent Shea discovered that the libvirt package set incorrect permissions on
the UNIX domain socket. A local attacker could use this issue to access
libvirt and escalate privileges.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
libvirt-daemon 6.0.0-0ubuntu8.3
libvirt-daemon-system 6.0.0-0ubuntu8.3
libvirt0 6.0.0-0ubuntu8.3
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
https://usn.ubuntu.com/4452-1
CVE-2020-15708
Package Information:
https://launchpad.net/ubuntu/+source/libvirt/6.0.0-0ubuntu8.3
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl8pq+sACgkQZWnYVadE
vpNUkg//VLT+nFqb5Ikd18OEM0tK2knnwWwsWkD+CYTB8/7D+4NlJY5NaV+BV49T
sPNdZnyNCpdQoFT+TB9+XqvEjjbOSGQkoz7fvyReKeptZOtU9g0BtYGgCSvTA6i0
oI2MlkBbq9Oi/XenBWAaDtbgQErmU3fD9mrzqhSnAVaEm5dhVb1p3EQoUFR7uNB/
MXpCRMvMluYNJrQbW2vPJ3SyACtL9pdZODNYM3Q2O9iUXOD4YXQZc9WlsRqtK90V
bV6yBY6TmUB1+WCiy7knj9R+WKuZio5w5xtt5tm/oFH7ntEVhnDzncxoClNj/37x
0aQx2Dz827cJd0p01SdjotJeIev4YY7hhBvN0QKP3XiD9txGC4e7NDjuiojJlfxk
drsMU6qjFWOXnPbQC9JQrYME/WMmT5sbEHS0y+LX/Jc50wTOzrOA0EneNy3p+UE5
NujMkNfX2+1ciN0+LrRpjH6oExxtOQu73MPxCfvjV2w6ZW2QHqd0UgVTtFPzLG0O
nZR5lYNSl7R6WUxD/NahZgTdw2q8yPuvZ/bDjrsJgQLclJ7KvkbELt0qj5eVCOw3
69PHzv5KbRYIGpkXlevBcPd2neijIEgMuCyfli6LzgsvTiJjN/3R+JyA7mIW7J0+
5fQQGwfUZIKaTgSCr4/SIDES5mQbOHEWX3rtpIcfqtojgI1fSfM=
=de50
—–END PGP SIGNATURE—–
—