Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10132

Опубликовано: 21 мая 2019
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.

A flaw was found in libvirt in version 4.1.0 and earlier. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvirtNot affected
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Storage 3libvirtNot affected
Red Hat Enterprise Linux 7libvirtFixedRHSA-2019:126423.05.2019
Red Hat Enterprise Linux 8virtFixedRHSA-2019:126823.05.2019
Red Hat Enterprise Linux 8 Advanced VirtualizationvirtFixedRHSA-2019:145511.06.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1706067libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter

EPSS

Процентиль: 70%
0.01411
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.

CVSS3: 8.8
nvd
около 7 лет назад

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.

CVSS3: 8.8
debian
около 7 лет назад

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.s ...

CVSS3: 8.8
github
около 4 лет назад

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.

oracle-oval
около 7 лет назад

ELSA-2019-4688: libvirt security update (IMPORTANT)

EPSS

Процентиль: 70%
0.01411
Низкий

8.8 High

CVSS3