cbcvebase.
CVE-2010-2239
published 2010-08-19

CVE-2010-2239: Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read…

medium4.4CVSS 3.1
AVLACMAuSCCINAN
Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read arbitrary files on the host OS via unspecified vectors.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlibvirt< libvirt 0.8.3-1 (bookworm)libvirt 0.8.3-1 (bookworm)
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
libvirtlibvirt
redhatlibvirt>= 0 < 0.8.3-10.8.3-1
redhatlibvirt>= 0 < 0.8.3-10.8.3-1
redhatlibvirt>= 0 < 0.8.3-10.8.3-1
redhatlibvirt>= 0 < 0.8.3-10.8.3-1

CVSS provenance

nvd4.4MEDIUMAV:L/AC:M/Au:S/C:C/I:N/A:N
osv4.4MEDIUM