CVE-2011-1146
published 2011-03-15CVE-2011-1146: libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial…
PriorityP431medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
1.53%
71.9th percentile
libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 0.8.8-3 (bookworm) | libvirt 0.8.8-3 (bookworm) |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 0.8.8-3 | 0.8.8-3 |
| redhat | libvirt | >= 0 < 0.8.8-3 | 0.8.8-3 |
| redhat | libvirt | >= 0 < 0.8.8-3 | 0.8.8-3 |
| redhat | libvirt | >= 0 < 0.8.8-3 | 0.8.8-3 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Libvirt vulnerability
vendor_ubuntu·2011-03-29
CVE-2011-1146 Libvirt vulnerability
Title: Libvirt vulnerability
Summary: An attacker could send crafted input to libvirt and cause it to crash.
Petr Matousek discovered that libvirt did not always honor read-only
connections. An attacker who is authorized to connect to the libvirt daemon
could exploit this to cause a denial of service via application crash.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvirt: several API calls do not honour read-only connection
vendor_redhat·2011-03-02·CVSS 7.2
CVE-2011-1146 [HIGH] libvirt: several API calls do not honour read-only connection
libvirt: several API calls do not honour read-only connection
libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.
Package: libvirt (Red Hat Enterprise Linux 5) - Affected
Debian
CVE-2011-1146: libvirt - libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operati...
vendor_debian·2011·CVSS 7.2
CVE-2011-1146 [HIGH] CVE-2011-1146: libvirt - libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operati...
libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.
Scope: local
bookworm: resolved (fixed in 0.8.8-3)
bullseye: resolved (fixed in 0.8.8-3)
forky: resolved (fixed in 0.8.8-3)
sid: resolved (fixed in 0.8.8-3)
trixie: resolved (fixed in 0.8.8-3)
GHSA
GHSA-69mw-4jhr-4j3r: libvirt
ghsa_unreviewed·2022-05-17·CVSS 7.2
CVE-2011-1146 [HIGH] GHSA-69mw-4jhr-4j3r: libvirt
libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.
OSV
CVE-2011-1146: libvirt
osv·2011-03-15·CVSS 7.2
CVE-2011-1146 [HIGH] CVE-2011-1146: libvirt
libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-1146 libvirt: several API calls do not honour read-only connection
bugzilla·2011-03-09·CVSS 6.9
CVE-2011-1146 [MEDIUM] CVE-2011-1146 libvirt: several API calls do not honour read-only connection
CVE-2011-1146 libvirt: several API calls do not honour read-only connection
Description of problem:
It has been found that several libvirt API calls (virNodeDeviceDettach, virNodeDeviceReset, virNodeDeviceReAttach, virDomainRevertToSnapshot, virDomainSnapshotDelete and virConnectDomainXMLToNative) did not honour read-only connection. Local attacker could use this flaw to crash the server (DoS) or possibly escalate his privileges.
Discussion:
Created libvirt tracking bugs for this issue
Affects: fedora-all [bug 683655]
---
Should virNodeDeviceReAttach also be added to the list?
---
(In reply to comment #4)
> Should virNodeDeviceReAttach also be added to the list?
Yes, I omitted it by mistake. Thanks Jim.
---
Also added virConnectDomainXMLToNative() after a full review and commite
Bugzilla
CVE-2011-1146 libvirt: several API calls do not honour read-only connection [fedora-all]
bugzilla·2011-03-09·CVSS 6.9
CVE-2011-1146 [MEDIUM] CVE-2011-1146 libvirt: several API calls do not honour read-only connection [fedora-all]
CVE-2011-1146 libvirt: several API calls do not honour read-only connection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=683650
Please note: this issue af
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=617773http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=71753cb7f7a16ff800381c0b5ee4e99eea92fed3http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056209.htmlhttp://lists.opensuse.org/opensuse-updates/2011-04/msg00022.htmlhttp://openwall.com/lists/oss-security/2011/03/09/3http://openwall.com/lists/oss-security/2011/03/10/5http://secunia.com/advisories/43670http://secunia.com/advisories/43780http://secunia.com/advisories/43897http://secunia.com/advisories/43917http://secunia.com/advisories/44069http://www.debian.org/security/2011/dsa-2194http://www.redhat.com/support/errata/RHSA-2011-0391.htmlhttp://www.securityfocus.com/bid/46820http://www.securitytracker.com/id?1025262http://www.ubuntu.com/usn/USN-1094-1http://www.vupen.com/english/advisories/2011/0694http://www.vupen.com/english/advisories/2011/0700http://www.vupen.com/english/advisories/2011/0794http://www.vupen.com/english/advisories/2011/0805https://bugzilla.novell.com/show_bug.cgi?id=678406https://bugzilla.redhat.com/show_bug.cgi?id=683650https://exchange.xforce.ibmcloud.com/vulnerabilities/66012http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=617773http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=71753cb7f7a16ff800381c0b5ee4e99eea92fed3http://lists.fedoraproject.org/pipermail/package-announce/2011-March/056209.htmlhttp://lists.opensuse.org/opensuse-updates/2011-04/msg00022.htmlhttp://openwall.com/lists/oss-security/2011/03/09/3http://openwall.com/lists/oss-security/2011/03/10/5http://secunia.com/advisories/43670http://secunia.com/advisories/43780http://secunia.com/advisories/43897http://secunia.com/advisories/43917http://secunia.com/advisories/44069http://www.debian.org/security/2011/dsa-2194http://www.redhat.com/support/errata/RHSA-2011-0391.htmlhttp://www.securityfocus.com/bid/46820http://www.securitytracker.com/id?1025262http://www.ubuntu.com/usn/USN-1094-1http://www.vupen.com/english/advisories/2011/0694http://www.vupen.com/english/advisories/2011/0700http://www.vupen.com/english/advisories/2011/0794http://www.vupen.com/english/advisories/2011/0805https://bugzilla.novell.com/show_bug.cgi?id=678406https://bugzilla.redhat.com/show_bug.cgi?id=683650https://exchange.xforce.ibmcloud.com/vulnerabilities/66012
2011-03-15
Published