SB2011031501 - Permissions, Privileges, and Access Controls in libvirt 



SB2011031501 - Permissions, Privileges, and Access Controls in libvirt

Published: March 15, 2011 Updated: August 11, 2020

Security Bulletin ID SB2011031501
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2011-1146)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.


Remediation

Install update from vendor's website.