Vulnerability Bulletins

DSA-4003 libvirt - security update

   
Affected software Debian
 
Daniel P. Berrange reported that Libvirt, a virtualisation abstractionlibrary, does not properly handle the default_tls_x509_verify (andrelated) parameters in qemu.conf when setting up TLS clients and serversin QEMU, resulting in TLS clients for character devices and disk deviceshaving verification turned off and ignoring any errors while validatingthe server certificate.

More info:

https://www.debian.org/security/2017/dsa-4003