ZeroHour

CVE-2019-10161

CVSS 3.1
7.8 high
EPSS
<1%p42
Published
()
Modified
Description

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.

Vendors
redhatcanonical
Products
libvirt, enterprise linux, virtualization, virtualization host, ubuntu linux
Weakness
CWE-284, CWE-22, CWE-862
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.