Wind River Support Network

HomeDefectsLIN7-11293
Fixed

LIN7-11293 : Security Advisory - libvirt - CVE-2019-10161

Created: Jul 31, 2019    Updated: Sep 22, 2019
Resolved Date: Aug 14, 2019
Found In Version: 7.0.0.1
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-10161 User=admin}

CVEs


Live chat
Online