Description
Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without setting the user-defined backing-store format, which allows guest OS users to read arbitrary files on the host OS via unspecified vectors.
CVSS vector
AV:L/AC:M/C:C/I:N/A:NExploitability: 2.7 | Impact: 6.9Integrity: None
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-9w2j-rv9v-ph7h: Red Hat libvirt, possibly 0↗2022-05-17 ▶ OSVCVE-2010-2239: Red Hat libvirt, possibly 0↗2010-08-19 ▶ CVEListCVE-2010-2239: Red Hat libvirt, possibly 0↗2010-08-19 ▶ 📋Vendor Advisories
3Ubuntulibvirt vulnerabilities↗2010-10-21 ▶ Red Hatlibvirt: not setting user defined backing store format when creating new image↗2010-07-12 ▶ DebianCVE-2010-2239: libvirt - Red Hat libvirt, possibly 0.6.0 through 0.8.2, creates new images without settin...↗2010 ▶ 💬Community
2BugzillaCVE-2010-2237 CVE-2010-2238 CVE-2010-2239 CVE-2010-2242 libvirt various flaws [fedora-all]↗2010-07-12 ▶ BugzillaCVE-2010-2239 libvirt: not setting user defined backing store format when creating new image↗2010-06-24 ▶