-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 24 Mar 2018 14:58:33 +0100 Source: libvirt Binary: libvirt-bin libvirt0 libvirt0-dbg libvirt-doc libvirt-dev python-libvirt Architecture: source all amd64 Version: 0.9.12.3-1+deb7u3 Distribution: wheezy-security Urgency: high Maintainer: Debian Libvirt Maintainers <pkg-libvirt-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: libvirt-bin - programs for the libvirt library libvirt-dev - development files for the libvirt library libvirt-doc - documentation for the libvirt library libvirt0 - library for interfacing with different virtualization systems libvirt0-dbg - library for interfacing with different virtualization systems python-libvirt - libvirt Python bindings Changes: libvirt (0.9.12.3-1+deb7u3) wheezy-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2018-5748 and CVE-2018-1064: Daniel P. Berrange and Peter Krempa of Red Hat discovered a flaw in libvirt. A lack of restriction for the amount of data read by QEMU Monitor socket can lead to a denial of service by exhaustion of memory resources. Checksums-Sha1: b8fb77e79b58a54f024c94206bda8c3210fe8d65 3114 libvirt_0.9.12.3-1+deb7u3.dsc 2e01abf468db7322439ce3ce5faef958e7156647 40949 libvirt_0.9.12.3-1+deb7u3.debian.tar.gz 7b8fbf335d6ebf60ec1fcd003ad12fcd1b36008b 2191386 libvirt-doc_0.9.12.3-1+deb7u3_all.deb 3bcb3d2ba724da520b5d9422063116514fdee32b 2500692 libvirt-bin_0.9.12.3-1+deb7u3_amd64.deb 281d58bd7eca63446ee0dc1058cca71a04669cf0 2142386 libvirt0_0.9.12.3-1+deb7u3_amd64.deb 23a75e7c913d73c6f1e3fe29645c75d8ab2e2952 8375528 libvirt0-dbg_0.9.12.3-1+deb7u3_amd64.deb 6ff5ff90555b0a44f5f61229e20aa1fe861b450e 2509560 libvirt-dev_0.9.12.3-1+deb7u3_amd64.deb 30ff74aba078addb940bfa892d6e24db5f3b192e 1431086 python-libvirt_0.9.12.3-1+deb7u3_amd64.deb Checksums-Sha256: 244d54b5cb1087b75a2f604b3f4bd3e95a376f689d0b3ff1768403ab1fb5e31f 3114 libvirt_0.9.12.3-1+deb7u3.dsc 89195ea3a3ed54d9d94eb0a7a25cfb4b5fdf2ae34cf82f452dc8fc2820ac18bd 40949 libvirt_0.9.12.3-1+deb7u3.debian.tar.gz edab8424f0721291b5cc3c690a3f5cf4536b2240febef6109650494f92419e7c 2191386 libvirt-doc_0.9.12.3-1+deb7u3_all.deb 984d88c3a239d700980f2311db9bc2568112d3b50155326ce4d8ff8b80819683 2500692 libvirt-bin_0.9.12.3-1+deb7u3_amd64.deb c2bc35235ae2fd81ee2a721781b872a13aab37ed9a4b1d9a0865fbd3f07b08c3 2142386 libvirt0_0.9.12.3-1+deb7u3_amd64.deb fea4a69d56ca00454199643055209563fc4e3a3958037974dc11d5eb7fa3050f 8375528 libvirt0-dbg_0.9.12.3-1+deb7u3_amd64.deb ab9f79a4282eb077e8db9b87b696c90c47fa588221a357c39d6fb71bd5559e55 2509560 libvirt-dev_0.9.12.3-1+deb7u3_amd64.deb b1c3ae039cece90b5f2f0518948da8b9d4f26b9f07c32499286bef131b85f3b0 1431086 python-libvirt_0.9.12.3-1+deb7u3_amd64.deb Files: f39799536656d2d750951e19b881c9d4 3114 libs optional libvirt_0.9.12.3-1+deb7u3.dsc 00ce2e3bea1c921ec7f3f2771a9b0d25 40949 libs optional libvirt_0.9.12.3-1+deb7u3.debian.tar.gz ba28d48f632d28aaac5d8d24325ab9d2 2191386 doc optional libvirt-doc_0.9.12.3-1+deb7u3_all.deb d116b3d936a9e2f276305b0297bd026a 2500692 admin optional libvirt-bin_0.9.12.3-1+deb7u3_amd64.deb b914298ec2212ec039c9f3949d52ed1f 2142386 libs optional libvirt0_0.9.12.3-1+deb7u3_amd64.deb c44629aeb09c9fbed6f4ec973d0bb165 8375528 debug extra libvirt0-dbg_0.9.12.3-1+deb7u3_amd64.deb 128865e09c0aba366a1725df63d332c2 2509560 libdevel optional libvirt-dev_0.9.12.3-1+deb7u3_amd64.deb 20d23055517cce783c7684c2fe6fdb81 1431086 python optional python-libvirt_0.9.12.3-1+deb7u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlq2aJhfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkAUoQAK/FT/WeL7MRo9Q/4c3ie4rdfCi0ebXxw3Ad kbvS3AY01NKEhlr1W7Lomi4WmpXGlO6fg1+NfEmPKrOoLa98ALZcrSnAWik9E3q1 +cUx3yAoNIAMcZtMMKbboOFOG8/mZYK0pPCJVWyXDU/Bnibu3AO9dqBs25mrZm/C 1AmglzGIi1w5P1H07NXFtqrV9d86AtvD028frUdopnUg9c0GcgqJZFr5GiqE3OQt ls4v3CTkzl79VPB7gkZCFmvW3iwSzDQ7ovFCzGBUKY0kC6DkbjUHpPsZU3fJquh9 yb8tk1R0If/uouTdVlldi/tZt4dDaQZLn9ry8ZSIJvpNNaW1QlkIFx4OuHi9YlTr cjAkDAEa+2d6zPaB2r9ugMIUmiPLyjNQSxzxN0+X9t0EupQ9V1JqyF7zQamrVEvu R8e+pX4F8CUxAf3OOjpvVRpua8qpVR6FLhku64zM01hUcWWGCNoMHIhprxheii6L fY5afZvWfiYCbMKkJyF5Ew5T5GCl6vQTXe7IO/OWMCs11/PFy4TqyM7wHGpbEMQy g3FCOGk5jihtnn/6/nj11lSbtnnZNnNJYf9zr6tHDzIrwDQBAyd27rcsD3XqiF0W ruEzqqH4eJu9iPdL21r1QrKlQVdaJpyee5aYw5BNlRNzp9kNxB+eU5Kdxv4R072y 0kO47Oe/ =4JIy -----END PGP SIGNATURE-----