]> xenbits.xensource.com Git - qemu-xen-4.0-testing.git/commit
Disable qemu monitor by default. The qemu monitor is an overly master
authorIan Jackson <ian.jackson@eu.citrix.com>
Thu, 6 Sep 2012 16:05:30 +0000 (17:05 +0100)
committerIan Jackson <Ian.Jackson@eu.citrix.com>
Thu, 6 Sep 2012 16:07:42 +0000 (17:07 +0100)
commiteaa1bd612f50d2f253738ed19e14981e4ede98a5
tree9ae37ecc0801b0f79963c67de943c13c18901d72
parent091149d364e893e643a5da3175c3f84d2163cb3e
Disable qemu monitor by default.  The qemu monitor is an overly
powerful feature which must be protected from untrusted (guest)
administrators.

Neither xl nor xend expect qemu to produce this monitor unless it is
explicitly requested.

This is a security problem, XSA-19.  Previously it was CVE-2007-0998
in Red Hat but we haven't dealt with it in upstream.  We hope to have
a new CVE for it here but we don't have one yet.

Signed-off-by: Ian Jackson <ian.jackson@eu.citrix.com>
(cherry picked from commit bacc0d302445c75f18f4c826750fb5853b60e7ca)
vl.c