Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20592
HistoryJun 24, 2019 - 12:21 a.m.

Arbitrary Code Execution

2019-06-2400:21:50
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.0004 Low

EPSS

Percentile

5.3%

libvirt is vulnerable to arbitrary code execution. The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() in libvirt APIs accept an “emulator” argument to specify the program providing emulation for a domain and libvirt will execute that program to probe the domain’s capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.