Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0236

Опубликовано: 22 янв. 2015
Источник: redhat
CVSS2: 2.9
EPSS Низкий

Описание

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.

It was discovered that the virDomainSnapshotGetXMLDesc() and virDomainSaveImageGetXMLDesc() functions did not sufficiently limit the usage of the VIR_DOMAIN_XML_SECURE flag when fine-grained ACLs were enabled. A remote attacker able to establish a connection to libvirtd could use this flaw to obtain certain sensitive information from the domain XML file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvirtWill not fix
Red Hat Enterprise Linux 6libvirtUnder investigation
Red Hat Storage 2.1libvirtUnder investigation
Red Hat Enterprise Linux 7libvirtFixedRHSA-2015:032305.03.2015
Red Hat Gluster Storage 3.1 for RHEL 7libvirtFixedRHSA-2015:032305.03.2015
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7libvirtFixedRHSA-2015:032305.03.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-285->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1184431libvirt: missing ACL check for the VIR_DOMAIN_XML_SECURE flag in save images and snapshots objects

EPSS

Процентиль: 61%
0.00423
Низкий

2.9 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.

nvd
больше 10 лет назад

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.

debian
больше 10 лет назад

libvirt before 1.2.12 allow remote authenticated users to obtain the V ...

github
больше 3 лет назад

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.

suse-cvrf
больше 9 лет назад

Security update for libvirt

EPSS

Процентиль: 61%
0.00423
Низкий

2.9 Low

CVSS2