It was found that several libvirt API calls did not honor the read-only
permission for connections. A local attacker able to establish a read-only
connection to libvirtd on a server could use this flaw to execute commands
that should be restricted to read-write connections, possibly leading to a
denial of service or privilege escalation. (CVE-2011-1146)
Note: Previously, using rpmbuild without the '--define "rhel 5"' option to
build the libvirt source RPM could failed with a "Failed build dependencies"
error for the device-mapper-devel package, as this -devel sub-package may not
be available. With this update, the -devel sub-package is no longer checked by
default as a dependency when building , allowing the libvirt source RPM to
build as expected.
---------------------------------------------------------------------------- SL
6.x