CVE-2019-3886
Summary
| CVE | CVE-2019-3886 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-04 16:29:00 UTC |
| Updated | 2023-02-12 23:38:00 UTC |
| Description | An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 29 Update: libvirt-4.7.0-5.fc29 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 30 Update: libvirt-5.1.0-9.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 29 Update: libvirt-4.7.0-5.fc29 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| 1694880 – (CVE-2019-3886) CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode |
CONFIRM |
bugzilla.redhat.com |
Exploit, Issue Tracking, Patch, Third Party Advisory |
| 1694880 – (CVE-2019-3886) CVE-2019-3886 libvirt: virsh domhostname command discloses guest hostname in readonly mode |
MISC |
bugzilla.redhat.com |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1294-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| [SECURITY] Fedora 30 Update: libvirt-5.1.0-9.fc30 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| libvirt CVE-2019-3886 Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| USN-4021-1: libvirt vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 672574 EulerOS Security Update for libvirt (EulerOS-SA-2023-1348)
- 900071 CBL-Mariner Linux Security Update for libvirt 6.1.0
- 903233 Common Base Linux Mariner (CBL-Mariner) Security Update for libvirt (2685)
- 905776 Common Base Linux Mariner (CBL-Mariner) Security Update for libvirt (2685-1)