PT-2011-5005 · Libvirt+1 · Libvirt+1
Publicado
2011-12-31
·
Atualizado
2024-06-15
·
CVE-2011-4600
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
libvirt versions prior to 0.9.9
Description
The issue is related to the networkReloadIptablesRules function in libvirt, which does not properly handle firewall rules on bridge networks when libvirtd is restarted. This might allow remote attackers to bypass intended access restrictions via a DNS or DHCP query.
Recommendations
For versions prior to 0.9.9, update to version 0.9.9 or later to resolve the issue. As a temporary workaround, consider restricting access to bridge networks to minimize the risk of exploitation.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ubuntu
Libvirt