[Libguestfs] CVE-2013-2124 (was: Re: ATTN: Denial of service attack possible on libguestfs)

Richard W.M. Jones rjones at redhat.com
Mon Jun 3 10:54:45 UTC 2013


The complete fix for CVE-2013-2124 requires:

https://github.com/libguestfs/libguestfs/commit/fa6a76050d82894365dfe32916903ef7fee3ffcd
https://github.com/libguestfs/libguestfs/commit/ae8bb84ecd46d7b6ef557a87725923ac8d09dce0
https://github.com/libguestfs/libguestfs/commit/1c9dfd079aa6d7893f72c5fd17656c847f72c8d6

It will be fixed upstream in:
  >= 1.20.8
  >= 1.22.2
  >= 1.23.2

Rich.

-- 
Richard Jones, Virtualization Group, Red Hat http://people.redhat.com/~rjones
Fedora Windows cross-compiler. Compile Windows programs, test, and
build Windows installers. Over 100 libraries supported.
http://fedoraproject.org/wiki/MinGW




More information about the Libguestfs mailing list