PT-2017-4106 · Red Hat+3 · Libvirt+3
Published
2017-10-05
·
Updated
2024-06-15
·
CVE-2017-1000256
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libvirt versions 2.3.0 and later
Description
The issue is related to errors in the certificate authentication procedure in the Libvirt virtualization management library. Exploitation of this issue allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The problem is caused by a bad default configuration where "verify-peer=no" is passed to QEMU by libvirt, resulting in a failure to validate SSL/TLS certificates by default.
Recommendations
For libvirt versions 2.3.0 and later, change the default configuration to "verify-peer=yes" to ensure validation of SSL/TLS certificates.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Libvirt