PT-2014-3438 · Red Hat+1 · Libvirt+1
Eric Blake
·
Published
2014-01-24
·
Updated
2024-06-15
·
CVE-2014-0028
CVSS v2.0
4.3
Medium
| Vector | AV:A/AC:M/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
libvirt versions 1.1.1 through 1.2.0
Description
The issue allows context-dependent attackers to bypass restrictions in ACLs, specifically the domain:getattr and connect:search domains restrictions, and obtain sensitive domain object information. This is achieved via a request to the (1)
virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.Recommendations
For libvirt versions 1.1.1 through 1.2.0, consider restricting access to the
virConnectDomainEventRegister and virConnectDomainEventRegisterAny functions in the event registration API until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Libvirt