Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10132

Опубликовано: 21 мая 2019
Источник: redhat
CVSS3: 8.8

Описание

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.

A flaw was found in libvirt in version 4.1.0 and earlier. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libvirtNot affected
Red Hat Enterprise Linux 6libvirtNot affected
Red Hat Storage 3libvirtNot affected
Red Hat Enterprise Linux 7libvirtFixedRHSA-2019:126423.05.2019
Red Hat Enterprise Linux 8virtFixedRHSA-2019:126823.05.2019
Red Hat Enterprise Linux 8 Advanced VirtualizationvirtFixedRHSA-2019:145511.06.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1706067libvirt: wrong permissions in systemd admin-sock due to missing SocketMode parameter

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 6 лет назад

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.

CVSS3: 8.8
nvd
больше 6 лет назад

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.

CVSS3: 8.8
debian
больше 6 лет назад

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.s ...

CVSS3: 8.8
github
больше 3 лет назад

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock and perform administrative tasks against the virtlockd and virtlogd daemons.

oracle-oval
больше 6 лет назад

ELSA-2019-4688: libvirt security update (IMPORTANT)

8.8 High

CVSS3