Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000256

Опубликовано: 31 окт. 2017
Источник: debian
EPSS Низкий

Описание

libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvirtfixed3.8.0-3package
libvirtnot-affectedjessiepackage
libvirtnot-affectedwheezypackage

Примечания

  • https://www.redhat.com/archives/libvirt-announce/2017-October/msg00001.html

  • https://security.libvirt.org/2017/0002.html

  • Broken by: http://libvirt.org/git/?p=libvirt.git;a=commit;h=ce61c16450d4992612d1fc6f39a39e79bfccead5 (master)

  • Fixed by: http://libvirt.org/git/?p=libvirt.git;a=commit;h=441d3eb6d1be940a67ce45a286602a967601b157 (master)

EPSS

Процентиль: 61%
0.00425
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.

CVSS3: 5
redhat
больше 7 лет назад

libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.

CVSS3: 8.1
nvd
больше 7 лет назад

libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.

CVSS3: 8.1
msrc
почти 5 лет назад

Описание отсутствует

suse-cvrf
больше 7 лет назад

Security update for libvirt

EPSS

Процентиль: 61%
0.00425
Низкий