Lucene search

K
cveRedhatCVE-2010-2237
HistoryAug 19, 2010 - 6:00 p.m.

CVE-2010-2237

2010-08-1918:00:03
CWE-264
redhat
web.nvd.nist.gov
37
cve-2010-2237
red hat
libvirt
security vulnerability
guest os
arbitrary file read
disk backing store

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:S/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

26.5%

Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.

Affected configurations

Nvd
Node
libvirtlibvirtMatch0.6.1
OR
libvirtlibvirtMatch0.6.2
OR
libvirtlibvirtMatch0.6.3
OR
libvirtlibvirtMatch0.6.4
OR
libvirtlibvirtMatch0.6.5
OR
libvirtlibvirtMatch0.7.0
OR
libvirtlibvirtMatch0.7.1
OR
libvirtlibvirtMatch0.7.2
OR
libvirtlibvirtMatch0.7.3
OR
libvirtlibvirtMatch0.7.4
OR
libvirtlibvirtMatch0.7.5
OR
libvirtlibvirtMatch0.7.6
OR
libvirtlibvirtMatch0.7.7
OR
libvirtlibvirtMatch0.8.0
OR
libvirtlibvirtMatch0.8.1
OR
libvirtlibvirtMatch0.8.2
VendorProductVersionCPE
libvirtlibvirt0.6.1cpe:2.3:a:libvirt:libvirt:0.6.1:*:*:*:*:*:*:*
libvirtlibvirt0.6.2cpe:2.3:a:libvirt:libvirt:0.6.2:*:*:*:*:*:*:*
libvirtlibvirt0.6.3cpe:2.3:a:libvirt:libvirt:0.6.3:*:*:*:*:*:*:*
libvirtlibvirt0.6.4cpe:2.3:a:libvirt:libvirt:0.6.4:*:*:*:*:*:*:*
libvirtlibvirt0.6.5cpe:2.3:a:libvirt:libvirt:0.6.5:*:*:*:*:*:*:*
libvirtlibvirt0.7.0cpe:2.3:a:libvirt:libvirt:0.7.0:*:*:*:*:*:*:*
libvirtlibvirt0.7.1cpe:2.3:a:libvirt:libvirt:0.7.1:*:*:*:*:*:*:*
libvirtlibvirt0.7.2cpe:2.3:a:libvirt:libvirt:0.7.2:*:*:*:*:*:*:*
libvirtlibvirt0.7.3cpe:2.3:a:libvirt:libvirt:0.7.3:*:*:*:*:*:*:*
libvirtlibvirt0.7.4cpe:2.3:a:libvirt:libvirt:0.7.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:S/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

26.5%