Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2xr-35cg-68vv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

EPSS

Процентиль: 53%
0.00306
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 10 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

redhat
около 14 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

CVSS3: 5.9
nvd
почти 10 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

CVSS3: 5.9
debian
почти 10 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in ...

EPSS

Процентиль: 53%
0.00306
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-284