From Mageia wiki
Jump to: navigation, search

MGASA-2013-0036

Date: February 6th, 2013
Affected releases: 2
Media: Core


Description:
Updated x11-driver-video-qxl package fixes security vulnerability:

A flaw was found in the way the host's qemu-kvm qxl driver and the guest's
X.Org qxl driver interacted when a SPICE connection terminated. A user able
to initiate a SPICE connection to a guest could use this flaw to make the
guest temporarily unavailable or, potentially (if the sysctl
kernel.softlockup_panic variable was set to "1" in the guest), crash the
guest (CVE-2013-0241).


Updated Packages:
i586:
x11-driver-video-qxl-0.0.16-4.1.mga2.i586.rpm
x11-driver-video-qxl-debug-0.0.16-4.1.mga2.i586.rpm

x86_64:
x11-driver-video-qxl-0.0.16-4.1.mga2.x86_64.rpm
x11-driver-video-qxl-debug-0.0.16-4.1.mga2.x86_64.rpm

SRPMS:
x11-driver-video-qxl-0.0.16-4.1.mga2.src.rpm


References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0241
https://rhn.redhat.com/errata/RHSA-2013-0218.html
https://bugs.mageia.org/show_bug.cgi?id=8938