Summary: | <app-emulation/libvirt-3.8.0-r1: TLS certificate verification disabled for clients | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | tamiko, virtualization |
Priority: | Normal | Flags: | stable-bot:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1503658 | ||
Whiteboard: | B3 [noglsa cve] | ||
Package list: |
dev-python/libvirt-python-3.8.0
app-emulation/libvirt-3.8.0-r1
|
Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() Fixed in 3.8.0-r1. Vulnerable version left in tree: 3.6.0 Let's wait until Friday for stabilization. commit 834dafc5a7928ecf8c1e643dd2879837d32d233c Author: Matthias Maier <tamiko@gentoo.org> Date: Wed Oct 25 14:46:02 2017 -0500 app-emulation/libvirt: fix CVE-2017-1000256, bug #635174 Package-Manager: Portage-2.3.8, Repoman-2.3.3 Arches, please stabilize =app-emulation/libvirt-3.8.0-r1 Target-keywords: amd64 x86 x86 stable amd6 stable Tree clean. commit 5d6f35fa50d81d06f2da8427d6ab6662100b38aa Author: Matthias Maier <tamiko@gentoo.org> Date: Tue Nov 14 18:19:38 2017 -0600 app-emulation/libvirt: drop vulnerable (bug #635174) Package-Manager: Portage-2.3.13, Repoman-2.3.4 Thank you all. GLSA Vote: No |