Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2xr-35cg-68vv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

EPSS

Процентиль: 76%
0.01783
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 10 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

redhat
больше 14 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

CVSS3: 5.9
nvd
больше 10 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

CVSS3: 5.9
debian
больше 10 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in ...

EPSS

Процентиль: 76%
0.01783
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-284