<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for libvirt</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2019:1753-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2019-07-20T06:25:34Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2019-07-20T06:25:34Z</InitialReleaseDate>
    <CurrentReleaseDate>2019-07-20T06:25:34Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for libvirt</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for libvirt fixes the following issues:

Security issues fixed: 	  

- CVE-2019-10161: Fixed virDomainSaveImageGetXMLDesc API which could accept a path
  parameter pointing anywhere on the system and potentially leading to execution 
  of a malicious file with root privileges by libvirtd (bsc#1138301). 
- CVE-2019-10166: Fixed an issue with virDomainManagedSaveDefineXML which could have 
  been used to alter the domain's config used for managedsave or execute arbitrary 
  emulator binaries (bsc#1138302).
- CVE-2019-10167: Fixed an issue with virConnectGetDomainCapabilities API which 
  could have been used to execute arbitrary emulators (bsc#1138303).
- CVE-2019-10168: Fixed an issue with virConnect*HypervisorCPU API which   
  could have been used to execute arbitrary emulators (bsc#1138305).

This update was imported from the SUSE:SLE-15-SP1:Update update project.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2019-1753</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00019.html</URL>
      <Description>E-Mail link for openSUSE-SU-2019:1753-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138301</URL>
      <Description>SUSE Bug 1138301</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138302</URL>
      <Description>SUSE Bug 1138302</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138303</URL>
      <Description>SUSE Bug 1138303</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1138305</URL>
      <Description>SUSE Bug 1138305</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-10161/</URL>
      <Description>SUSE CVE CVE-2019-10161 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-10166/</URL>
      <Description>SUSE CVE CVE-2019-10166 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-10167/</URL>
      <Description>SUSE CVE CVE-2019-10167 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2019-10168/</URL>
      <Description>SUSE CVE CVE-2019-10168 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE Leap 15.1">
      <Branch Type="Product Name" Name="openSUSE Leap 15.1">
        <FullProductName ProductID="openSUSE Leap 15.1" CPE="cpe:/o:opensuse:leap:15.1">openSUSE Leap 15.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-5.1.0-lp151.7.3.1">libvirt-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-admin-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-admin-5.1.0-lp151.7.3.1">libvirt-admin-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-bash-completion-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-bash-completion-5.1.0-lp151.7.3.1">libvirt-bash-completion-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-client-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-client-5.1.0-lp151.7.3.1">libvirt-client-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-5.1.0-lp151.7.3.1">libvirt-daemon-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-config-network-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-config-network-5.1.0-lp151.7.3.1">libvirt-daemon-config-network-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1">libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1">libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1">libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1">libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-network-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-network-5.1.0-lp151.7.3.1">libvirt-daemon-driver-network-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1">libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1">libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1">libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1">libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-hooks-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-hooks-5.1.0-lp151.7.3.1">libvirt-daemon-hooks-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-lxc-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-lxc-5.1.0-lp151.7.3.1">libvirt-daemon-lxc-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-qemu-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-qemu-5.1.0-lp151.7.3.1">libvirt-daemon-qemu-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-daemon-xen-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-daemon-xen-5.1.0-lp151.7.3.1">libvirt-daemon-xen-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-devel-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-devel-5.1.0-lp151.7.3.1">libvirt-devel-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-devel-32bit-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-devel-32bit-5.1.0-lp151.7.3.1">libvirt-devel-32bit-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-doc-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-doc-5.1.0-lp151.7.3.1">libvirt-doc-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-libs-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-libs-5.1.0-lp151.7.3.1">libvirt-libs-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-lock-sanlock-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-lock-sanlock-5.1.0-lp151.7.3.1">libvirt-lock-sanlock-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libvirt-nss-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="libvirt-nss-5.1.0-lp151.7.3.1">libvirt-nss-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="wireshark-plugin-libvirt-5.1.0-lp151.7.3.1">
      <FullProductName ProductID="wireshark-plugin-libvirt-5.1.0-lp151.7.3.1">wireshark-plugin-libvirt-5.1.0-lp151.7.3.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libvirt-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-5.1.0-lp151.7.3.1">libvirt-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-admin-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-admin-5.1.0-lp151.7.3.1">libvirt-admin-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-bash-completion-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-bash-completion-5.1.0-lp151.7.3.1">libvirt-bash-completion-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-client-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-client-5.1.0-lp151.7.3.1">libvirt-client-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-5.1.0-lp151.7.3.1">libvirt-daemon-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-config-network-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-config-network-5.1.0-lp151.7.3.1">libvirt-daemon-config-network-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1">libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1">libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1">libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1">libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-network-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-network-5.1.0-lp151.7.3.1">libvirt-daemon-driver-network-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1">libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1">libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1">libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1">libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1">libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-hooks-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-hooks-5.1.0-lp151.7.3.1">libvirt-daemon-hooks-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-lxc-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-lxc-5.1.0-lp151.7.3.1">libvirt-daemon-lxc-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-qemu-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-qemu-5.1.0-lp151.7.3.1">libvirt-daemon-qemu-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-daemon-xen-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-daemon-xen-5.1.0-lp151.7.3.1">libvirt-daemon-xen-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-devel-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-devel-5.1.0-lp151.7.3.1">libvirt-devel-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-devel-32bit-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-devel-32bit-5.1.0-lp151.7.3.1">libvirt-devel-32bit-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-doc-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-doc-5.1.0-lp151.7.3.1">libvirt-doc-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-libs-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-libs-5.1.0-lp151.7.3.1">libvirt-libs-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-lock-sanlock-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-lock-sanlock-5.1.0-lp151.7.3.1">libvirt-lock-sanlock-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libvirt-nss-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:libvirt-nss-5.1.0-lp151.7.3.1">libvirt-nss-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="wireshark-plugin-libvirt-5.1.0-lp151.7.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.1">
      <FullProductName ProductID="openSUSE Leap 15.1:wireshark-plugin-libvirt-5.1.0-lp151.7.3.1">wireshark-plugin-libvirt-5.1.0-lp151.7.3.1 as a component of openSUSE Leap 15.1</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.</Note>
    </Notes>
    <CVE>CVE-2019-10161</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.1:libvirt-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-admin-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-bash-completion-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-client-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-config-network-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-network-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-hooks-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-lxc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-qemu-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-xen-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-devel-32bit-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-devel-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-doc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-libs-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-lock-sanlock-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-nss-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:wireshark-plugin-libvirt-5.1.0-lp151.7.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-10161.html</URL>
        <Description>CVE-2019-10161</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1138301</URL>
        <Description>SUSE Bug 1138301</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.</Note>
    </Notes>
    <CVE>CVE-2019-10166</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.1:libvirt-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-admin-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-bash-completion-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-client-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-config-network-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-network-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-hooks-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-lxc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-qemu-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-xen-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-devel-32bit-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-devel-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-doc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-libs-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-lock-sanlock-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-nss-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:wireshark-plugin-libvirt-5.1.0-lp151.7.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-10166.html</URL>
        <Description>CVE-2019-10166</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1138302</URL>
        <Description>SUSE Bug 1138302</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.</Note>
    </Notes>
    <CVE>CVE-2019-10167</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.1:libvirt-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-admin-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-bash-completion-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-client-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-config-network-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-network-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-hooks-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-lxc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-qemu-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-xen-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-devel-32bit-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-devel-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-doc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-libs-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-lock-sanlock-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-nss-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:wireshark-plugin-libvirt-5.1.0-lp151.7.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-10167.html</URL>
        <Description>CVE-2019-10167</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1138303</URL>
        <Description>SUSE Bug 1138303</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.</Note>
    </Notes>
    <CVE>CVE-2019-10168</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.1:libvirt-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-admin-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-bash-completion-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-client-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-config-network-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-config-nwfilter-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-interface-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-libxl-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-lxc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-network-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-nodedev-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-nwfilter-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-qemu-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-secret-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-core-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-disk-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-gluster-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-iscsi-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-logical-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-mpath-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-rbd-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-driver-storage-scsi-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-hooks-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-lxc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-qemu-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-daemon-xen-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-devel-32bit-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-devel-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-doc-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-libs-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-lock-sanlock-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:libvirt-nss-5.1.0-lp151.7.3.1</ProductID>
        <ProductID>openSUSE Leap 15.1:wireshark-plugin-libvirt-5.1.0-lp151.7.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/opensuse-security-announce/2019-07/msg00019.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2019-10168.html</URL>
        <Description>CVE-2019-10168</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1138305</URL>
        <Description>SUSE Bug 1138305</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1138582</URL>
        <Description>SUSE Bug 1138582</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
