← Back

CVE-2015-5313

nvd nist
Published: Apr 11, 2016Modified: May 6, 2026

JSON object

Loading...
2.5
Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.0 / Impact: 1.4
Source: NVD

Description

Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write to arbitrary files via a .. (dot dot) in a volume name.

Affected (1)

Products: Redhat: Libvirt
1 product
Libvirt
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

Timeline

No history available yet.