SUSE update for Recommended update for libvirt



Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2016-6453
CWE-ID CWE-89
Exploitation vector Network
Public exploit N/A
Vulnerable software
SUSE Linux Enterprise Micro
Operating systems & Components / Operating system

libvirt-daemon-driver-storage-rbd-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-rbd
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-iscsi
Operating systems & Components / Operating system package or component

libvirt-client
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-logical
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-network
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-secret
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-core-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-secret-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-qemu
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-logical-debuginfo
Operating systems & Components / Operating system package or component

libvirt-libs-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-qemu-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-scsi
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-qemu
Operating systems & Components / Operating system package or component

libvirt-libs
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-iscsi-direct
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-disk
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-mpath-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-scsi-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-core
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-interface
Operating systems & Components / Operating system package or component

libvirt-client-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-nodedev-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-iscsi-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-disk-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-nwfilter
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-network-debuginfo
Operating systems & Components / Operating system package or component

libvirt-debugsource
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-iscsi-direct-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage-mpath
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-nodedev
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-interface-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-storage
Operating systems & Components / Operating system package or component

libvirt-daemon-driver-nwfilter-debuginfo
Operating systems & Components / Operating system package or component

libvirt-daemon-debuginfo
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) SQL injection

EUVDB-ID: #VU1085

Risk: Medium

CVSSv4.0: 6.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2016-6453

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to inject SQL commands on the target system.
The weakness is due to improper input validation. By supplying a specially crafted parameter value, a remote attacker cam execute SQL commands.
Successful exploitation may result in the vulnerable system compromise.

Mitigation

Update the affected package Recommended update for libvirt to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Micro: 5.5

libvirt-daemon-driver-storage-rbd-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-rbd: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-iscsi: before 9.0.0-150500.6.23.1

libvirt-client: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-logical: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-network: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-secret: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-core-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-secret-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-qemu: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-logical-debuginfo: before 9.0.0-150500.6.23.1

libvirt-libs-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-qemu-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-scsi: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-qemu: before 9.0.0-150500.6.23.1

libvirt-libs: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-iscsi-direct: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-disk: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-mpath-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-scsi-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-core: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-interface: before 9.0.0-150500.6.23.1

libvirt-client-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-nodedev-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-iscsi-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-disk-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-nwfilter: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-network-debuginfo: before 9.0.0-150500.6.23.1

libvirt-debugsource: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-iscsi-direct-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage-mpath: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-nodedev: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-interface-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-storage: before 9.0.0-150500.6.23.1

libvirt-daemon-driver-nwfilter-debuginfo: before 9.0.0-150500.6.23.1

libvirt-daemon-debuginfo: before 9.0.0-150500.6.23.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2024/suse-ru-20241933-2/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###