PT-2019-2575 · Libvirt+5 · Libvirt+5

Doran Moppert

·

Publicado

2019-06-13

·

Atualizado

2024-06-15

·

CVE-2019-10166

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libvirtd versions 4.x.x through 4.10.0 libvirtd versions 5.x.x through 5.4.0
Description The issue is related to insufficient access control in the virDomainManagedSaveDefineXML() API, allowing readonly clients to modify managed save state files. If a managed save was created by a privileged user, a local attacker could modify this file to execute an arbitrary program when the domain is resumed. This could potentially allow an attacker to change arbitrary files by sending a specially crafted request.
Recommendations For libvirtd versions 4.x.x through 4.10.0, update to version 4.10.1 or later. For libvirtd versions 5.x.x through 5.4.0, update to version 5.4.1 or later. As a temporary workaround, consider restricting access to the virDomainManagedSaveDefineXML() API until a patch is available.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2222
ALT-PU-2019-2225
BDU:2019-02445
CESA-2019_1579
CESA-2019_1580
CVE-2019-10166
MGASA-2019-0390
OPENSUSE-SU-2019:1672-1
OPENSUSE-SU-2019:1753-1
OPENSUSE-SU-2019_1672-1
OPENSUSE-SU-2019_1753-1
OPENSUSE-SU-2024:11008-1
RHSA-2019:1579
RHSA-2019:1580
RHSA-2019:1699
RHSA-2019:1762
RHSA-2019_1579
RHSA-2019_1580
SUSE-SU-2019:1599-1
SUSE-SU-2019:1637-1
SUSE-SU-2019:1643-1
USN-4047-1

Produtos afetados

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libvirt