Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20738
HistoryJul 09, 2019 - 2:58 a.m.

Arbitrary Command Execution

2019-07-0902:58:30
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.0004 Low

EPSS

Percentile

5.3%

libvirt is vulnerable to Arbitrary Command Execution. The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs accept an “emulator” argument to specify the program providing emulation for a domain. An attacker could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

CPENameOperatorVersion
libvirt.soeq0.5000.0