PT-2016-1796 · Libvirt+2 · Libvirt+2
Han Han
·
Publicado
2015-10-23
·
Atualizado
2024-06-15
·
CVE-2015-5247
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libvirt versions 1.2.14 through 1.2.19
Description
The issue is related to insufficient access control in the virStorageVolCreateXML API of the libvirt library, which manages virtualization. This can be exploited by a remote attacker to cause a denial of service, resulting in the libvirtd crash, by triggering a failed unlink after creating a volume on a root squash NFS pool.
Recommendations
For libvirt versions 1.2.14 through 1.2.19, consider restricting access to the virStorageVolCreateXML API to prevent remote authenticated users from exploiting the issue. As a temporary workaround, avoid using the virStorageVolCreateXML API to create volumes on root squash NFS pools until a patch is available.
Correção
DoS
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Ubuntu
Libvirt