← Back

CVE-2019-10161

nvd nist
Published: Jul 30, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.

Affected (7)

4 products
Libvirt
Enterprise Linux
Virtualization
Virtualization Host
1 product
Ubuntu Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Before 4.10.1
From 5.0.0 to 5.4.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 8.0
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 4.0
Version 4.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 14.04

References (10)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.