Описание
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 4.0.0-1ubuntu8.12 |
cosmic | released | 4.6.0-2ubuntu3.8 |
devel | released | 5.4.0-0ubuntu3 |
disco | released | 5.0.0-1ubuntu2.4 |
esm-infra-legacy/trusty | not-affected | code not present |
esm-infra/bionic | not-affected | 4.0.0-1ubuntu8.12 |
esm-infra/xenial | not-affected | code not present |
precise/esm | not-affected | code not present |
trusty | ignored | end of standard support |
trusty/esm | not-affected | code not present |
Показывать по
EPSS
4.6 Medium
CVSS2
7.8 High
CVSS3
Связанные уязвимости
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x. ...
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
Уязвимость функции virDomainManagedSaveDefineXML библиотеки libvirtd, позволяющая нарушителю изменять произвольные файлы
EPSS
4.6 Medium
CVSS2
7.8 High
CVSS3