Wind River Support Network

HomeDefectsLIN1018-4140
Fixed

LIN1018-4140 : Security Advisory - libvirt - CVE-2019-10132

Created: May 23, 2019    Updated: Jun 18, 2019
Resolved Date: Jun 16, 2019
Found In Version: 10.18.44.1
Fix Version: 10.18.44.8
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-10132 User=admin}

CVEs


Live chat
Online