Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-25637
HistoryOct 06, 2020 - 12:00 a.m.

CVE-2020-25637

2020-10-0600:00:00
ubuntu.com
ubuntu.com
18

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

14.2%

A double free memory issue was found to occur in the libvirt API, in
versions before 6.8.0, responsible for requesting information about network
interfaces of a running QEMU domain. This flaw affects the polkit access
control driver. Specifically, clients connecting to the read-write socket
with limited ACL permissions could use this flaw to crash the libvirt
daemon, resulting in a denial of service, or potentially escalate their
privileges on the system. The highest threat from this vulnerability is to
data confidentiality and integrity as well as system availability.

Bugs

Notes

Author Note
mdeslaur Read-only clients can’t exploit this flaw. Clients connecting to the read-write socket can exploit this to crash libvirt or possibly execute code, but on Ubuntu, access to the read-write socket already grants root-equivalent permissions, so this flaw has limited impact. Setting priority to negligible.
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlibvirt< 4.0.0-1ubuntu8.21UNKNOWN
ubuntu20.04noarchlibvirt< 6.0.0-0ubuntu8.16UNKNOWN
ubuntu14.04noarchlibvirt< anyUNKNOWN
ubuntu16.04noarchlibvirt< anyUNKNOWN

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

14.2%