Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4600

Опубликовано: 09 дек. 2011
Источник: redhat
CVSS2: 2.6

Описание

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

Отчет

This issue affect Red Hat Enterprise Linux 6 and has been addressed via https://rhn.redhat.com/errata/RHBA-2012-0013.html. Red Hat Enterprise Linux 5 is not affected. The Red Hat Security Response Team has rated this issue as having low security impact. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvirtNot affected
Red Hat Enterprise Linux 6libvirtAffected
Red Hat Enterprise Linux 6.2 EUS - Server and Compute Node OnlylibvirtFixedRHBA-2012:001317.01.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=765964libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 10 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

CVSS3: 5.9
nvd
почти 10 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

CVSS3: 5.9
debian
почти 10 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in ...

CVSS3: 5.9
github
больше 3 лет назад

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.

2.6 Low

CVSS2