Hide Forgot
Description of problem: It has been found that several libvirt API calls (virNodeDeviceDettach, virNodeDeviceReset, virNodeDeviceReAttach, virDomainRevertToSnapshot, virDomainSnapshotDelete and virConnectDomainXMLToNative) did not honour read-only connection. Local attacker could use this flaw to crash the server (DoS) or possibly escalate his privileges.
Created libvirt tracking bugs for this issue Affects: fedora-all [bug 683655]
Should virNodeDeviceReAttach also be added to the list?
(In reply to comment #4) > Should virNodeDeviceReAttach also be added to the list? Yes, I omitted it by mistake. Thanks Jim.
Also added virConnectDomainXMLToNative() after a full review and commited upstream: http://libvirt.org/git/?p=libvirt.git;a=commitdiff;h=71753cb7f7a16ff800381c0b5ee4e99eea92fed3;hp=13c00dde3171b3a38d23cceb3f9151cb6cac3dad Daniel
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2011:0391 https://rhn.redhat.com/errata/RHSA-2011-0391.html