Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-5160

Опубликовано: 20 авг. 2018
Источник: debian
EPSS Низкий

Описание

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvirtfixed2.2.0-1package
libvirtno-dsajessiepackage
libvirtno-dsawheezypackage
libvirtend-of-lifesqueezepackage

Примечания

  • libvirt side fixed with: http://libvirt.org/git/?p=libvirt.git;a=commit;h=d53d465083edeb64cc7b78249c030734c0d91c6b

  • https://libvirt.org/git/?p=libvirt.git;a=commit;h=a1344f70a128921e7fe7213da7c1afbc962fba9c

  • and needs at least Qemu 2.6, which is satisfied in Stretch and later.

  • https://bugzilla.redhat.com/show_bug.cgi?id=1182074 (not yet opened)

  • https://www.redhat.com/archives/libvir-list/2011-November/msg00853.html

  • Needs changes in QEMU for passing passwords. Affects at least iSCSI and rbd/ceph.

EPSS

Процентиль: 35%
0.00145
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 7 лет назад

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

CVSS3: 3.3
redhat
около 10 лет назад

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

CVSS3: 5.5
nvd
около 7 лет назад

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

CVSS3: 5.5
github
больше 3 лет назад

libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.

oracle-oval
почти 9 лет назад

ELSA-2016-2577: libvirt security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 35%
0.00145
Низкий