PT-2010-3834 · Red Hat · Libvirt

Petr Matousek

·

Publicado

2010-08-19

·

Atualizado

2010-10-30

·

CVE-2010-2237

CVSS v2.0

4.4

Média

VetorAV:L/AC:M/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat libvirt versions 0.6.1 through 0.8.2
Description The issue allows guest OS users to potentially read arbitrary files on the host OS, and possibly have other unspecified impacts, via unknown vectors. This occurs because Red Hat libvirt looks up disk backing stores without referring to the user-defined main disk format.
Recommendations For versions 0.6.1 through 0.8.2, update to a version that fixes this issue to prevent guest OS users from reading arbitrary files on the host OS. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2237

Produtos afetados

Libvirt