Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10694
HistoryJan 15, 2019 - 8:50 a.m.

Authorization Bypass

2019-01-1508:50:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.003

Percentile

71.0%

libvirt is vulnerable to authorization bypass attacks. The vulnerability exists as the networkReloadIptablesRules function of network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

EPSS

0.003

Percentile

71.0%