LWN.net Logo

libvirt: privilege escalation

Package(s):libvirt CVE #(s):CVE-2009-0036
Created:March 19, 2009 Updated:March 25, 2009
Description: libvirt has a privilege escalation vulnerability. From the Red hat alert:

libvirt_proxy, a setuid helper application allowing non-privileged users to communicate with the hypervisor, was discovered to not properly validate user requests. Local users could use this flaw to cause a stack-based buffer overflow in libvirt_proxy, possibly allowing them to run arbitrary code with root privileges. (CVE-2009-0036)

Alerts:
Red Hat RHSA-2009:0382-01 2009-03-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds