Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 629462 - <app-emulation/libvirt-3.6.0: virsh does not sanitize address parameters used by SSH
Summary: <app-emulation/libvirt-3.6.0: virsh does not sanitize address parameters used...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-08-31 14:24 UTC by Agostino Sarubbo
Modified: 2017-09-27 23:17 UTC (History)
2 users (show)

See Also:
Package list:
=app-emulation/libvirt-3.6.0 =dev-python/libvirt-python-3.6.0
Runtime testing required: No
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2017-08-31 14:24:13 UTC
From ${URL} :

It was found that virsh does not properly sanitize addresses before passing them onto SSH. For example, `virsh -c 'qemu+ssh://root@-help/system' list` will list SSH's help message.

No known or even potential exploitation vector is known and this issue is considered of low threat and priority.

Upstream patch:

http://libvirt.org/git/?p=libvirt.git;a=commit;h=e4cb8500810a310a10a6cb359e1b53fac03ed597


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Matthias Maier gentoo-dev 2017-09-01 02:05:00 UTC
Patch applied to version 3.6.0.


commit 02110c0d470e8549a31ae8bf953c8bd514185c68
Author: Matthias Maier <tamiko@gentoo.org>
Date:   Thu Aug 31 20:48:57 2017 -0500

    app-emulation/libvirt: version bump to 3.6.0, bug #627780
    
    Package-Manager: Portage-2.3.6, Repoman-2.3.3
Comment 2 Matthias Maier gentoo-dev 2017-09-01 14:20:18 UTC
Let's stabilize in a week, not immediately.

This issue hardly justifies rushing stabilization.
Comment 3 Aaron Bauman (RETIRED) gentoo-dev 2017-09-01 15:45:32 UTC
(In reply to Matthias Maier from comment #2)
> Let's stabilize in a week, not immediately.
> 
> This issue hardly justifies rushing stabilization.

Very well. Keep in mind we will call for stabilization if the maintainer puts "stable" on the whiteboard.  If you want to hold please mark it "stable?" This assists us in sorting/identifying bugs pending stable calls.
Comment 4 Matthias Maier gentoo-dev 2017-09-07 16:05:13 UTC
Arches, please stabilize
  =app-emulation/libvirt-3.6.0
  =dev-python/libvirt-python-3.6.0
Comment 5 Agostino Sarubbo gentoo-dev 2017-09-20 09:59:56 UTC
amd64 stable
Comment 6 Thomas Deutschmann (RETIRED) gentoo-dev 2017-09-23 14:18:01 UTC
x86 stable


@ Maintainer(s): Please cleanup and drop <app-emulation/libvirt-3.6.0 and <dev-python/libvirt-python-3.6.0!
Comment 7 Matthias Maier gentoo-dev 2017-09-27 15:16:47 UTC
commit c122fff41902ba3749531883044eb6121ff4dc49
Author: Matthias Maier <tamiko@gentoo.org>
Date:   Wed Sep 27 10:05:24 2017 -0500

    app-emulation/libvirt: drop old, bug #629462
    
    Package-Manager: Portage-2.3.8, Repoman-2.3.3

commit ed84c3e512aa1c20678857517d370931cf9cca55
Author: Matthias Maier <tamiko@gentoo.org>
Date:   Wed Sep 27 10:04:15 2017 -0500

    dev-python/libvirt-python: drop old, bug #629462
    
    Package-Manager: Portage-2.3.8, Repoman-2.3.3
Comment 8 Aaron Bauman (RETIRED) gentoo-dev 2017-09-27 23:17:32 UTC
GLSA Vote: No