Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jeremy Nickurak

#53358of 53,633
2.1Total CVSS
Vulnerabilities · 1
PT-2010-3838
2.1
2010-08-10
Red Hat · Libvirt · CVE-2010-2242
**Name of the Vulnerable Software and Affected Versions** Red Hat libvirt versions 0.2.0 through 0.8.2 **Description** The issue allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values. This can be demonstrated by copying and deleting an NFS directory tree, exploiting improper mappings of privileged source ports in iptables rules. **Recommendations** For Red Hat libvirt versions 0.2.0 through 0.8.2, consider restricting access to privileged source ports to minimize the risk of exploitation. As a temporary workaround, restrict the use of iptables rules that map privileged source ports until a patch is available.