CVE-2010-2242
published 2010-08-19CVE-2010-2242: Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.42%
34.4th percentile
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 0.8.3-1 (bookworm) | libvirt 0.8.3-1 (bookworm) |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_ubuntu4.4MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt regression
vendor_ubuntu·2010-11-08·CVSS 4.4
CVE-2010-2238 [MEDIUM] libvirt regression
Title: libvirt regression
Summary: This update restores 'host_device' support for domain XML on Ubuntu 10.04
LTS.
USN-1008-1 fixed vulnerabilities in libvirt. The upstream fixes for
CVE-2010-2238 changed the behavior of libvirt such that the domain
XML could not specify 'host_device' as the qemu sub-type. While libvirt
0.8.3 and later will longer support specifying this sub-type, this
update restores the old behavior on Ubuntu 10.04 LTS.
We apologize for the inconvenience.
Original advisory details:
It was discovered that libvirt would probe disk backing stores without
consulting the defined format for the disk. A privileged attacker in the
guest could exploit this to read arbitrary files on the host. This issue
only affected Ubuntu 10.04 LTS. By default, guests are confined by an
App
Ubuntu
libvirt update
vendor_ubuntu·2010-10-23·CVSS 4.4
[MEDIUM] libvirt update
Title: libvirt update
Summary: This update reenables recent bug fixes.
USN-1008-1 fixed vulnerabilities in libvirt. The update for Ubuntu 10.04
LTS reverted a recent bug fix update. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that libvirt would probe disk backing stores without
consulting the defined format for the disk. A privileged attacker in the
guest could exploit this to read arbitrary files on the host. This issue
only affected Ubuntu 10.04 LTS. By default, guests are confined by an
AppArmor profile which provided partial protection against this flaw.
(CVE-2010-2237, CVE-2010-2238)
It was discovered that libvirt would create new VMs without setting a
backing store format. A privileged attacker in the guest cou
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2010-10-21·CVSS 4.4
CVE-2010-2237 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Guest VMs could be made to circumvent security protections to access
resources on the host.
It was discovered that libvirt would probe disk backing stores without
consulting the defined format for the disk. A privileged attacker in the
guest could exploit this to read arbitrary files on the host. This issue
only affected Ubuntu 10.04 LTS. By default, guests are confined by an
AppArmor profile which provided partial protection against this flaw.
(CVE-2010-2237, CVE-2010-2238)
It was discovered that libvirt would create new VMs without setting a
backing store format. A privileged attacker in the guest could exploit this
to read arbitrary files on the host. This issue did not affect Ubuntu 8.04
LTS. In Ubuntu 9.10 and later guests are confined by an
Ubuntu
Virtinst update
vendor_ubuntu·2010-10-21·CVSS 4.4
[MEDIUM] Virtinst update
Title: Virtinst update
Summary: Updated virtinst for use with the new libvirt.
Libvirt in Ubuntu 10.04 LTS now no longer probes qemu disks for the image
format and defaults to 'raw' when the format is not specified in the XML.
This change in behavior breaks virt-install --import because virtinst in
Ubuntu 10.04 LTS did not allow for specifying a disk format and does not
specify a format in the XML. This update adds the 'format=' option when
specifying a disk. For example, to import an existing VM which uses a qcow2
disk format, use somthing like the following:
virt-install --connect=qemu:///session --name test-import --ram=256 \
--disk path=,format=qcow2 --import
For more information, see man 1 virt-install.
Original advisory details:
It was discovered that libvirt would probe disk b
Red Hat
libvirt: improperly mapped source privileged ports may allow for obtaining privileged resources on the host
vendor_redhat·2010-07-12·CVSS 2.1
CVE-2010-2242 [LOW] libvirt: improperly mapped source privileged ports may allow for obtaining privileged resources on the host
libvirt: improperly mapped source privileged ports may allow for obtaining privileged resources on the host
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
Package: libvirt (Red Hat Enterprise Linux 5) - Affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-2242: libvirt - Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mapping...
vendor_debian·2010·CVSS 2.1
CVE-2010-2242 [LOW] CVE-2010-2242: libvirt - Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mapping...
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
Scope: local
bookworm: resolved (fixed in 0.8.3-1)
bullseye: resolved (fixed in 0.8.3-1)
forky: resolved (fixed in 0.8.3-1)
sid: resolved (fixed in 0.8.3-1)
trixie: resolved (fixed in 0.8.3-1)
GHSA
GHSA-j4r2-c3hx-6f4x: Red Hat libvirt 0
ghsa_unreviewed·2022-05-17
CVE-2010-2242 [LOW] GHSA-j4r2-c3hx-6f4x: Red Hat libvirt 0
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
OSV
CVE-2010-2242: Red Hat libvirt 0
osv·2010-08-19·CVSS 2.1
CVE-2010-2242 [LOW] CVE-2010-2242: Red Hat libvirt 0
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
Suricata
GPL FTP MKD overflow
suricata·2010-09-23
CVE-1999-0368 GPL FTP MKD overflow
GPL FTP MKD overflow
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL FTP MKD overflow"; flow:established,to_server; content:"MKD "; isdataat:100,relative; reference:bugtraq,113; reference:bugtraq,2242; reference:cve,1999-0368; classtype:attempted-admin; sid:2100349; rev:14; metadata:created_at 2010_09_23, cve CVE_1999_0368, signature_severity Unknown, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
No public exploits indexed.
Bugzilla
CVE-2010-2237 CVE-2010-2238 CVE-2010-2239 CVE-2010-2242 libvirt various flaws [fedora-all]
bugzilla·2010-07-12·CVSS 4.4
CVE-2010-2237 [MEDIUM] CVE-2010-2237 CVE-2010-2238 CVE-2010-2239 CVE-2010-2242 libvirt various flaws [fedora-all]
CVE-2010-2237 CVE-2010-2238 CVE-2010-2239 CVE-2010-2242 libvirt various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=607810
Please note: this issue
Bugzilla
CVE-2010-2242 libvirt: improperly mapped source privileged ports may allow for obtaining privileged resources on the host
bugzilla·2010-06-09·CVSS 2.1
CVE-2010-2242 [LOW] CVE-2010-2242 libvirt: improperly mapped source privileged ports may allow for obtaining privileged resources on the host
CVE-2010-2242 libvirt: improperly mapped source privileged ports may allow for obtaining privileged resources on the host
Jeremy Nickurak reported an issue with how libvirt creates iptables rules when guest systems are setup for masquerading. The iptables rule will be of the following format:
# iptables-save -t nat
# Generated by iptables-save v1.4.7 on Wed Jun 9 14:59:03 2010
*nat
:PREROUTING ACCEPT [45:5146]
:POSTROUTING ACCEPT [889:54117]
:OUTPUT ACCEPT [889:54117]
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
COMMIT
# Completed on Wed Jun 9 14:59:03 2010
With masquerading, outgoing connections will have their source-port mapped to a NAT-selected port, and the iptables default is for privileged ports to be mapped to privileged (
(su to that new UID)
user-wit
http://libvirt.org/news.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044520.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044579.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://ubuntu.com/usn/usn-1008-1http://ubuntu.com/usn/usn-1008-2http://ubuntu.com/usn/usn-1008-3http://www.redhat.com/support/errata/RHSA-2010-0615.htmlhttp://www.vupen.com/english/advisories/2010/2062http://www.vupen.com/english/advisories/2010/2763https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/591943https://bugzilla.redhat.com/show_bug.cgi?id=602455http://libvirt.org/news.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044520.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044579.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.htmlhttp://ubuntu.com/usn/usn-1008-1http://ubuntu.com/usn/usn-1008-2http://ubuntu.com/usn/usn-1008-3http://www.redhat.com/support/errata/RHSA-2010-0615.htmlhttp://www.vupen.com/english/advisories/2010/2062http://www.vupen.com/english/advisories/2010/2763https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/591943https://bugzilla.redhat.com/show_bug.cgi?id=602455
2010-08-19
Published