[libvirt-users] Vulnerability in gnuTLS

Hello, There is a vulnerability described in the gnuTLS library which is used in libvirt: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3466 We are using libvirt 0.8.7 on Windows so my question is: Is there already a windows version with a newer gnuTLS library which has a fix for the mentioned vulnerability? --- Sent from my Fujitsu Lifebook E782 With best regards Alfred Boehme Senior Developer PSO PM&D SV E SW 4 [cid:image001.gif@01CF8617.647717D0] FUJITSU Mies-van-der-Rohe-Str. 8, 80807 Munich, Germany Tel: +49 (89) 62060 2990 Mob: +49 (171) 62060 329 2990 E-mail: Alfred.Boehme@ts.fujitsu.com<mailto:Alfred.Boehme@ts.fujitsu.com> Web: ts.fujitsu.com<http://ts.fujitsu.com/> Company details: Fujitsu Technology Solutions GmbH / ts.fujitsu.com/imprint<http://ts.fujitsu.com/imprint.html> This communication contains information that is confidential, proprietary in nature and/or privileged. It is for the exclusive use of the intended recipient(s). If you are not the intended recipient(s) or the person responsible for delivering it to the intended recipient(s), please note that any form of dissemination, distribution or copying of this communication is strictly prohibited and may be unlawful. If you have received this communication in error, please immediately notify the sender and delete the original communication. Thank you for your cooperation. Please be advised that neither Fujitsu, its affiliates, its employees or agents accept liability for any errors, omissions or damages caused by delays of receipt or by any virus infection in this message or its attachments, or which may otherwise arise as a result of this e-mail transmission.

On Thu, Jun 12, 2014 at 08:24:42AM +0200, Boehme, Alfred wrote:
Hello,
There is a vulnerability described in the gnuTLS library which is used in libvirt:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3466
We are using libvirt 0.8.7 on Windows so my question is: Is there already a windows version with a newer gnuTLS library which has a fix for the mentioned vulnerability?
If you're using libvirt 0.8.7 you've got far more than just the gnutls vuln to worry about - that's a libvirt more than 3 years old now. I'd suggest your upgrade everything to something modern. Any recent libvirt is capable of being built for Windows using the Mingw64 toolchain. We don't provide official builds ourself but you can get Fedora Mingw64 packages for libvirt & everything it depends on. Regards, Daniel -- |: http://berrange.com -o- http://www.flickr.com/photos/dberrange/ :| |: http://libvirt.org -o- http://virt-manager.org :| |: http://autobuild.org -o- http://search.cpan.org/~danberr/ :| |: http://entangle-photo.org -o- http://live.gnome.org/gtk-vnc :|
participants (2)
-
Boehme, Alfred
-
Daniel P. Berrange