CVE-2010-2242
Summary
| CVE | CVE-2010-2242 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-08-19 18:00:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Libvirt | Libvirt | 0.2.0 | All | All | All |
| Application | Libvirt | Libvirt | 0.2.1 | All | All | All |
| Application | Libvirt | Libvirt | 0.2.2 | All | All | All |
| Application | Libvirt | Libvirt | 0.2.3 | All | All | All |
| Application | Libvirt | Libvirt | 0.3.0 | All | All | All |
| Application | Libvirt | Libvirt | 0.3.1 | All | All | All |
| Application | Libvirt | Libvirt | 0.3.2 | All | All | All |
| Application | Libvirt | Libvirt | 0.3.3 | All | All | All |
| Application | Libvirt | Libvirt | 0.4.0 | All | All | All |
| Application | Libvirt | Libvirt | 0.4.1 | All | All | All |
| Application | Libvirt | Libvirt | 0.4.2 | All | All | All |
| Application | Libvirt | Libvirt | 0.4.3 | All | All | All |
| Application | Libvirt | Libvirt | 0.4.4 | All | All | All |
| Application | Libvirt | Libvirt | 0.4.6 | All | All | All |
| Application | Libvirt | Libvirt | 0.5.0 | All | All | All |
| Application | Libvirt | Libvirt | 0.5.1 | All | All | All |
| Application | Libvirt | Libvirt | 0.6.0 | All | All | All |
| Application | Libvirt | Libvirt | 0.6.1 | All | All | All |
| Application | Libvirt | Libvirt | 0.6.2 | All | All | All |
| Application | Libvirt | Libvirt | 0.6.3 | All | All | All |
| Application | Libvirt | Libvirt | 0.6.4 | All | All | All |
| Application | Libvirt | Libvirt | 0.6.5 | All | All | All |
| Application | Libvirt | Libvirt | 0.7.0 | All | All | All |
| Application | Libvirt | Libvirt | 0.7.1 | All | All | All |
| Application | Libvirt | Libvirt | 0.7.2 | All | All | All |
| Application | Libvirt | Libvirt | 0.7.3 | All | All | All |
| Application | Libvirt | Libvirt | 0.7.4 | All | All | All |
| Application | Libvirt | Libvirt | 0.7.5 | All | All | All |
| Application | Libvirt | Libvirt | 0.7.6 | All | All | All |
| Application | Libvirt | Libvirt | 0.7.7 | All | All | All |
| Application | Libvirt | Libvirt | 0.8.0 | All | All | All |
| Application | Libvirt | Libvirt | 0.8.1 | All | All | All |
| Application | Libvirt | Libvirt | 0.8.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #591943 “improperly mapped source privileged ports may allow...” : Bugs : “libvirt” package : Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| USN-1008-2: Virtinst update | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| USN-1008-1: libvirt vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [SECURITY] Fedora 12 Update: libvirt-0.8.2-1.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 13 Update: libvirt-0.8.2-1.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| USN-1008-3: libvirt update | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | ubuntu.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| libvirt: Releases | af854a3a-2127-422b-91ae-364da2661108 | libvirt.org | Vendor Advisory |
| Bug 602455 – CVE-2010-2242 libvirt: improperly mapped source privileged ports may allow for obtaining privileged resources on the host | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.