Debian Security Advisory 4003-1

Discussion in 'News Aggregator' started by Packet Storm, 20 Oct 2017.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 4003-1 - Daniel P. Berrange reported that Libvirt, a virtualisation abstraction library, does not properly handle the default_tls_x509_verify (and related) parameters in qemu.conf when setting up TLS clients and servers in QEMU, resulting in TLS clients for character devices and disk devices having verification turned off and ignoring any errors while validating the server certificate.

    Continue reading...
     

Share This Page

Loading...