PT-2017-4106 · Red Hat+3 · Libvirt+3
Publicado
2017-10-05
·
Atualizado
2024-06-15
·
CVE-2017-1000256
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libvirt versions 2.3.0 and later
Description
The issue is related to errors in the certificate authentication procedure in the Libvirt virtualization management library. Exploitation of this issue allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The problem is caused by a bad default configuration where "verify-peer=no" is passed to QEMU by libvirt, resulting in a failure to validate SSL/TLS certificates by default.
Recommendations
For libvirt versions 2.3.0 and later, change the default configuration to "verify-peer=yes" to ensure validation of SSL/TLS certificates.
Exploit
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Libvirt