Логотип exploitDog
bind:"GHSA-g9cg-gvh5-48hm" OR bind:"CVE-2019-10166"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-g9cg-gvh5-48hm" OR bind:"CVE-2019-10166"

Количество 14

Количество 14

github логотип

GHSA-g9cg-gvh5-48hm

почти 4 года назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

EPSS: Низкий
ubuntu логотип

CVE-2019-10166

больше 6 лет назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2019-10166

почти 7 лет назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2019-10166

больше 6 лет назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2019-10166

больше 6 лет назад

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x. ...

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2019-02445

почти 7 лет назад

Уязвимость функции virDomainManagedSaveDefineXML библиотеки libvirtd, позволяющая нарушителю изменять произвольные файлы

CVSS2: 4.6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1672-1

больше 6 лет назад

Security update for libvirt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1637-1

почти 7 лет назад

Security update for libvirt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1599-1

почти 7 лет назад

Security update for libvirt

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1753-1

больше 6 лет назад

Security update for libvirt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1643-1

почти 7 лет назад

Security update for libvirt

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1580

больше 6 лет назад

ELSA-2019-1580: virt:ol security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-1579

почти 7 лет назад

ELSA-2019-1579: libvirt security and bug fix update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2019-4714

больше 6 лет назад

ELSA-2019-4714: libvirt security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-g9cg-gvh5-48hm

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x. ...

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
fstec логотип
BDU:2019-02445

Уязвимость функции virDomainManagedSaveDefineXML библиотеки libvirtd, позволяющая нарушителю изменять произвольные файлы

CVSS2: 4.6
0%
Низкий
почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1672-1

Security update for libvirt

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1637-1

Security update for libvirt

почти 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1599-1

Security update for libvirt

почти 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1753-1

Security update for libvirt

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1643-1

Security update for libvirt

почти 7 лет назад
oracle-oval логотип
ELSA-2019-1580

ELSA-2019-1580: virt:ol security update (IMPORTANT)

больше 6 лет назад
oracle-oval логотип
ELSA-2019-1579

ELSA-2019-1579: libvirt security and bug fix update (IMPORTANT)

почти 7 лет назад
oracle-oval логотип
ELSA-2019-4714

ELSA-2019-4714: libvirt security update (IMPORTANT)

больше 6 лет назад

Уязвимостей на страницу