Lucene search

K
cveRedhatCVE-2011-1146
HistoryMar 15, 2011 - 5:55 p.m.

CVE-2011-1146

2011-03-1517:55:05
CWE-264
redhat
web.nvd.nist.gov
55
cve
2011
1146
red hat
libvirt
denial of service
remote attackers
code execution
api operations

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.075

Percentile

94.1%

libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.

Affected configurations

Nvd
Node
redhatlibvirtMatch0.8.8
VendorProductVersionCPE
redhatlibvirt0.8.8cpe:2.3:a:redhat:libvirt:0.8.8:*:*:*:*:*:*:*

References

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.075

Percentile

94.1%