Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10161


It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.


Published

2019-07-30T23:15:12.120

Last Modified

2024-11-21T04:18:32.930

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    CWE-22
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat libvirt < 4.10.1 Yes
Application redhat libvirt < 5.4.1 Yes
Operating System redhat enterprise_linux 6.0 Yes
Operating System redhat enterprise_linux 7.0 Yes
Operating System redhat enterprise_linux 8.0 Yes
Application redhat virtualization 4.0 Yes
Application redhat virtualization_host 4.0 Yes
Operating System redhat enterprise_linux 7.0 No
Operating System canonical ubuntu_linux 14.04 Yes

References