[SECURITY] Fedora 15 Update: xen-4.1.0-2.fc15

updates at fedoraproject.org updates at fedoraproject.org
Thu May 19 04:52:37 UTC 2011


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-6859
2011-05-11 05:46:13
--------------------------------------------------------------------------------

Name        : xen
Product     : Fedora 15
Version     : 4.1.0
Release     : 2.fc15
URL         : http://xen.org/
Summary     : Xen is a virtual machine monitor
Description :
This package contains the XenD daemon and xm command line
tools, needed to manage virtual machines running under the
Xen hypervisor

--------------------------------------------------------------------------------
Update Information:

Overflows in kernel decompression can allow root on xen PV guest to gain
privileged access to base domain, or access to xen configuration info.
Lack of error checking could allow DoS attack from guest. [CVE-2011-1583]
Don't require /usr/bin/qemu-nbd as it isn't used at present.
--------------------------------------------------------------------------------
ChangeLog:

* Mon May  9 2011 Michael Young <m.a.young at durham.ac.uk> - 4.1.0-2
- Overflows in kernel decompression can allow root on xen PV guest to gain
  privileged access to base domain, or access to xen configuration info.
  Lack of error checking could allow DoS attack from guest [CVE-2011-1583]
- Don't require /usr/bin/qemu-nbd as it isn't used at present.
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update xen' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list