Lucene search

K
cve[email protected]CVE-2019-10161
HistoryJul 30, 2019 - 11:15 p.m.

CVE-2019-10161

2019-07-3023:15:12
CWE-284
CWE-862
CWE-22
web.nvd.nist.gov
327
2
libvirtd
cve-2019-10161
vulnerability
access control
arbitrary files
denial of service
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.

Affected configurations

Vulners
NVD
Node
libvirtlibvirtRange4.10.1
OR
libvirtlibvirtRange5.4.1
VendorProductVersionCPE
libvirtlibvirt*cpe:2.3:a:libvirt:libvirt:*:*:*:*:*:*:*:*
libvirtlibvirt*cpe:2.3:a:libvirt:libvirt:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "libvirt",
    "vendor": "Libvirt",
    "versions": [
      {
        "status": "affected",
        "version": "fixed in 4.10.1"
      },
      {
        "status": "affected",
        "version": "fixed in 5.4.1"
      }
    ]
  }
]

Social References

More

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%