Lucene search

K
ubuntuUbuntuUSN-1094-1
HistoryMar 29, 2011 - 12:00 a.m.

Libvirt vulnerability

2011-03-2900:00:00
ubuntu.com
38

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.075

Percentile

94.1%

Releases

  • Ubuntu 10.10
  • Ubuntu 10.04
  • Ubuntu 9.10

Packages

  • libvirt - Libvirt virtualization toolkit

Details

Petr Matousek discovered that libvirt did not always honor read-only
connections. An attacker who is authorized to connect to the libvirt daemon
could exploit this to cause a denial of service via application crash.

OSVersionArchitecturePackageVersionFilename
Ubuntu9.10noarchlibvirt0< 0.7.0-1ubuntu13.3UNKNOWN
Ubuntu9.10noarchlibvirt-bin< 0.7.0-1ubuntu13.3UNKNOWN
Ubuntu9.10noarchlibvirt-dev< 0.7.0-1ubuntu13.3UNKNOWN
Ubuntu9.10noarchlibvirt0-dbg< 0.7.0-1ubuntu13.3UNKNOWN
Ubuntu9.10noarchpython-libvirt< 0.7.0-1ubuntu13.3UNKNOWN
Ubuntu10.10noarchlibvirt0< 0.8.3-1ubuntu14.1UNKNOWN
Ubuntu10.10noarchlibvirt-bin< 0.8.3-1ubuntu14.1UNKNOWN
Ubuntu10.10noarchlibvirt-dev< 0.8.3-1ubuntu14.1UNKNOWN
Ubuntu10.10noarchlibvirt0-dbg< 0.8.3-1ubuntu14.1UNKNOWN
Ubuntu10.10noarchpython-libvirt< 0.8.3-1ubuntu14.1UNKNOWN
Rows per page:
1-10 of 151

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.9

Confidence

Low

EPSS

0.075

Percentile

94.1%