LWN.net Logo

libvirt: multiple vulnerabilities

Package(s):libvirt CVE #(s):CVE-2010-2242 CVE-2010-2237 CVE-2010-2238 CVE-2010-2239
Created:July 27, 2010 Updated:November 9, 2010
Description: From the Red Hat bugzilla: Jeremy Nickurak reported an issue with how libvirt creates iptables rules when guest systems are setup for masquerading. (CVE-2010-2242)

From the Red Hat bugzilla: It was found that libvirt did not honour the user defined main disk format in guest XML when looking up disk backing stores in the security drivers. This could be possibly exploited by privileged guest user to access arbitrary files on the host. (CVE-2010-2237)

From the Red Hat bugzilla: It was found that libvirt did not extract the defined disk backing store format when recursing into disk image backing stores in the security drivers. This could be possibly exploited by privileged guest user to access arbitrary files on the host. (CVE-2010-2238)

From the Red Hat bugzilla: It was found that libvirt did not explicitly set the user defined backing store format when creating new image. This results in images being created with an potentially insecure configuration, preventing applications from opening backing stores without resorting to probing. A privileged guest user could use this flaw to access arbitrary files on the host. (CVE-2010-2239)

Alerts:
Ubuntu USN-1008-4 2010-11-08
Ubuntu USN-1008-3 2010-10-23
openSUSE openSUSE-SU-2010:0620-1 2010-09-16
SUSE SUSE-SR:2010:017 2010-09-21
Ubuntu USN-1008-2 2010-10-21
CentOS CESA-2010:0615 2010-08-11
Red Hat RHSA-2010:0615-01 2010-08-10
Fedora FEDORA-2010-11021 2010-07-13
Fedora FEDORA-2010-10960 2010-07-13
Ubuntu USN-1008-1 2010-10-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds