[libvirt] [PATCH 0/3] Followup fix for CVE-2013-4311

Daniel P. Berrange berrange at redhat.com
Mon Sep 23 11:46:24 UTC 2013


From: "Daniel P. Berrange" <berrange at redhat.com>

The initial fix for CVE-2013-4311 had a flaw which affected
the ACL code only. The first patch fixes that flaw, the next
two add a test suite for the code in question.

Daniel P. Berrange (3):
  Fix typo in identity code which is pre-requisite for CVE-2013-4311
  Add a virNetSocketNewConnectSockFD method
  Add test case for virNetServerClient object identity code

 cfg.mk                         |   2 +-
 src/libvirt_private.syms       |   1 +
 src/rpc/virnetserverclient.c   |   2 +-
 src/rpc/virnetsocket.c         |  18 +++++
 src/rpc/virnetsocket.h         |   2 +
 tests/Makefile.am              |  14 +++-
 tests/virnetserverclientmock.c |  64 +++++++++++++++++
 tests/virnetserverclienttest.c | 159 +++++++++++++++++++++++++++++++++++++++++
 8 files changed, 259 insertions(+), 3 deletions(-)
 create mode 100644 tests/virnetserverclientmock.c
 create mode 100644 tests/virnetserverclienttest.c

-- 
1.8.3.1




More information about the libvir-list mailing list