PT-2016-1796 · Libvirt+2 · Libvirt+2

Han Han

·

Publicado

2015-10-23

·

Atualizado

2024-06-15

·

CVE-2015-5247

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libvirt versions 1.2.14 through 1.2.19
Description The issue is related to insufficient access control in the virStorageVolCreateXML API of the libvirt library, which manages virtualization. This can be exploited by a remote attacker to cause a denial of service, resulting in the libvirtd crash, by triggering a failed unlink after creating a volume on a root squash NFS pool.
Recommendations For libvirt versions 1.2.14 through 1.2.19, consider restricting access to the virStorageVolCreateXML API to prevent remote authenticated users from exploiting the issue. As a temporary workaround, avoid using the virStorageVolCreateXML API to create volumes on root squash NFS pools until a patch is available.

Correção

DoS

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1925
BDU:2016-01128
CVE-2015-5247
OPENSUSE-SU-2024:10209-1
USN-2867-1

Produtos afetados

Alt Linux
Ubuntu
Libvirt