It was found that several libvirt API calls did not honor the read-only
permission for connections. A local attacker able to establish a read-only
connection to libvirtd on a server could use this flaw to execute commands
that should be restricted to read-write connections, possibly leading to a
denial of service or privilege escalation. (CVE-2011-1146)
Note: Previously, using rpmbuild without the '--define "rhel 5"' option to
build the libvirt source RPM could failed with a "Failed build
dependencies" error for the device-mapper-devel package, as this -devel
sub-package may not be available. With this update, the -devel sub-package
is no longer checked by default as a dependency when building , allowing
the libvirt source RPM to build as expected.
----------------------------------------------------------------------------
SL 5.x