From nobody Wed May 14 15:05:10 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of redhat.com designates 209.132.183.28 as permitted sender) client-ip=209.132.183.28; envelope-from=libvir-list-bounces@redhat.com; helo=mx1.redhat.com; Authentication-Results: mx.zohomail.com; spf=pass (zoho.com: domain of redhat.com designates 209.132.183.28 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass(p=none dis=none) header.from=redhat.com Return-Path: Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) by mx.zohomail.com with SMTPS id 1520962167332657.24975700224; Tue, 13 Mar 2018 10:29:27 -0700 (PDT) Received: from smtp.corp.redhat.com (int-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id C357E883C3; Tue, 13 Mar 2018 17:29:25 +0000 (UTC) Received: from colo-mx.corp.redhat.com (colo-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.20]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 8F15F7EA25; Tue, 13 Mar 2018 17:29:25 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id 4CA21180BAE5; Tue, 13 Mar 2018 17:29:25 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx04.intmail.prod.int.rdu2.redhat.com [10.11.54.4]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id w2DHRncI005688 for ; Tue, 13 Mar 2018 13:27:50 -0400 Received: by smtp.corp.redhat.com (Postfix) id C2F2B202322B; Tue, 13 Mar 2018 17:27:49 +0000 (UTC) Received: from t460.redhat.com (unknown [10.33.36.27]) by smtp.corp.redhat.com (Postfix) with ESMTP id 53E8C2024CAB; Tue, 13 Mar 2018 17:27:49 +0000 (UTC) From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: libvir-list@redhat.com Date: Tue, 13 Mar 2018 17:27:36 +0000 Message-Id: <20180313172737.24214-4-berrange@redhat.com> In-Reply-To: <20180313172737.24214-1-berrange@redhat.com> References: <20180313172737.24214-1-berrange@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.78 on 10.11.54.4 X-loop: libvir-list@redhat.com Subject: [libvirt] [PATCH security-notice 3/4] LSN-2018-0003 / CVE-2018-6764 - Insecure usage of NSS modules during container startup X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Sender: libvir-list-bounces@redhat.com Errors-To: libvir-list-bounces@redhat.com X-Scanned-By: MIMEDefang 2.79 on 10.5.11.11 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.26]); Tue, 13 Mar 2018 17:29:26 +0000 (UTC) X-ZohoMail: RSF_0 Z_629925259 SPT_0 Signed-off-by: Daniel P. Berrang=C3=A9 --- notices/2018/0003.xml | 269 ++++++++++++++++++++++++++++++++++++++++++++++= ++++ 1 file changed, 269 insertions(+) create mode 100644 notices/2018/0003.xml diff --git a/notices/2018/0003.xml b/notices/2018/0003.xml new file mode 100644 index 0000000..2c53626 --- /dev/null +++ b/notices/2018/0003.xml @@ -0,0 +1,269 @@ + + 2018-0003 + + Insecure usage of NSS modules during container startup + + + + + + + + + + + + + + + + Lubomir Rintel + lkundrak@v3.sk + + + Lubomir Rintel + lkundrak@v3.sk + + + Daniel P. Berrang=C3=A9 + berrange@redhat.com + + + + + 20180127 + 20180207 + 20180207 + + + + + + + + libvirt.git + + + master + v0.4.4 + v0.4.6 + v0.5.0 + v0.5.1 + v0.6.0 + v0.6.1 + v0.6.2 + v0.6.3 + v0.6.4 + v0.6.5 + v0.7.0 + v0.7.1 + v0.7.2 + v0.7.3 + v0.7.4 + v0.7.5 + v0.7.6 + v0.7.7 + v0.8.0 + v0.8.1 + v0.8.2 + v0.8.3 + v0.8.4 + v0.8.5 + v0.8.6 + v0.8.7 + v0.8.8 + v0.9.0 + v0.9.1 + v0.9.2 + v0.9.3 + v0.9.4 + v0.9.5 + v0.9.6 + v0.9.7 + v0.9.8 + v0.9.9 + v0.9.10 + v0.9.11 + v0.9.12 + v0.9.13 + v0.10.0 + v0.10.1 + v0.10.2 + v1.0.0 + v1.0.1 + v1.0.2 + v1.0.3 + v1.0.4 + v1.0.5 + v1.0.6 + v1.1.0 + v1.1.1 + v1.1.2 + v1.1.3 + v1.1.4 + v1.2.0 + v1.2.1 + v1.2.2 + v1.2.3 + v1.2.4 + v1.2.5 + v1.2.6 + v1.2.7 + v1.2.8 + v1.2.9 + v1.2.10 + v1.2.11 + v1.2.12 + v1.2.13 + v1.2.14 + v1.2.15 + v1.2.16 + v1.2.17 + v1.2.18 + v1.2.19 + v1.2.20 + v1.2.21 + v1.3.0 + v1.3.1 + v1.3.2 + v1.3.3 + v1.3.4 + v1.3.5 + v2.0.0 + v2.1.0 + v2.2.0 + v2.3.0 + v2.4.0 + v2.5.0 + v3.0.0 + v3.1.0 + v3.2.0 + v3.3.0 + v3.4.0 + v3.5.0 + v3.6.0 + v3.7.0 + v3.8.0 + v3.9.0 + v3.10.0 + v4.0.0 + v4.1.0 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + 759b4d1b0fe5f4d84d98b99153dfa7ac289dd167 + c2dc6698c88fb591639e542c8ecb0076c54f3dfb + + + v0.9.6-maint + v0.9.6.1 + v0.9.6.2 + v0.9.6.3 + v0.9.6.4 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v0.9.11-maint + v0.9.11.1 + v0.9.11.2 + v0.9.11.3 + v0.9.11.4 + v0.9.11.5 + v0.9.11.6 + v0.9.11.7 + v0.9.11.8 + v0.9.11.9 + v0.9.11.10 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v0.9.12-maint + v0.9.12.1 + v0.9.12.2 + v0.9.12.3 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v0.10.2-maint + v0.10.2.1 + v0.10.2.2 + v0.10.2.3 + v0.10.2.4 + v0.10.2.5 + v0.10.2.6 + v0.10.2.7 + v0.10.2.8 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v1.0.5-maint + v1.0.5.1 + v1.0.5.2 + v1.0.5.3 + v1.0.5.4 + v1.0.5.5 + v1.0.5.6 + v1.0.5.7 + v1.0.5.8 + v1.0.5.9 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v1.1.3-maint + v1.1.3.1 + v1.1.3.2 + v1.1.3.3 + v1.1.3.4 + v1.1.3.5 + v1.1.3.6 + v1.1.3.7 + v1.1.3.8 + v1.1.3.9 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v1.2.9-maint + v1.2.9.1 + v1.2.9.2 + v1.2.9.3 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v1.2.13-maint + v1.2.13.1 + v1.2.13.2 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v1.2.18-maint + v1.2.18.1 + v1.2.18.2 + v1.2.18.3 + v1.2.18.4 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v1.3.3-maint + v1.3.3.1 + v1.3.3.2 + v1.3.3.3 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v2.2-maint + v2.2.1 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + v3.2-maint + v3.2.1 + 9ae41a71ac457994b7ca975e9eec7c3fc13ac10= 1 + + + + --=20 2.14.3 -- libvir-list mailing list libvir-list@redhat.com https://www.redhat.com/mailman/listinfo/libvir-list