PT-2018-3357 · Red Hat+4 · Libvirt+5

Pedro Sampaio

·

Publicado

2018-02-07

·

Atualizado

2019-10-03

·

CVE-2018-6764

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: libvirt (affected versions not specified)
Description: The issue is related to the util/virlog.c in libvirt, which does not properly determine the hostname on LXC container startup. This allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module. The exploitation of this issue may allow an attacker to access confidential data, compromise their integrity, and cause a denial of service.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Origin Validation Error

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2448
BDU:2020-00584
CESA-2018_3113
CVE-2018-6764
DSA-4137-1
MGASA-2018-0153
OPENSUSE-SU-2018_0939-1
RHSA-2018:3113
RHSA-2018_3113
SUSE-SU-2018:0861-1
SUSE-SU-2018:0920-1
USN-3576-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libvirt