CVE-2019-10161
Summary
| CVE | CVE-2019-10161 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-30 23:15:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs. |
Risk And Classification
Problem Types: CWE-22 | CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Application | Redhat | Libvirt | All | All | All | All |
| Application | Redhat | Libvirtd | All | All | All | All |
| Application | Redhat | Libvirtd | All | All | All | All |
| Application | Redhat | Virtualization | 4.0 | All | All | All |
| Application | Redhat | Virtualization Host | 4.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| libvirt: Multiple vulnerabilities (GLSA 202003-18) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| libvirt privilege escalation vulnerabilities - Red Hat Customer Portal | CONFIRM | access.redhat.com | Third Party Advisory |
| 1720115 – (CVE-2019-10161) CVE-2019-10161 libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API | CONFIRM | bugzilla.redhat.com | Exploit, Issue Tracking, Mitigation, Third Party Advisory |
| USN-4047-2: libvirt update vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| libvirt.org Git - libvirt.git/commit | CONFIRM | libvirt.org | Vendor Advisory |
| libvirt.org Git - libvirt.git/commit | libvirt.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.