PT-2017-4106 · Red Hat+3 · Libvirt+3

Published

2017-10-05

·

Updated

2024-06-15

·

CVE-2017-1000256

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libvirt versions 2.3.0 and later
Description The issue is related to errors in the certificate authentication procedure in the Libvirt virtualization management library. Exploitation of this issue allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The problem is caused by a bad default configuration where "verify-peer=no" is passed to QEMU by libvirt, resulting in a failure to validate SSL/TLS certificates by default.
Recommendations For libvirt versions 2.3.0 and later, change the default configuration to "verify-peer=yes" to ensure validation of SSL/TLS certificates.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2546
ALT-PU-2017-2777
ALT-PU-2018-2448
BDU:2021-03338
CVE-2017-1000256
DSA-4003-1
MGASA-2018-0153
OPENSUSE-SU-2024:11008-1
SUSE-SU-2017:2850-1
SUSE-SU-2017_2850-1
USN-3576-1

Affected Products

Alt Linux
Suse
Ubuntu
Libvirt