CVE-2011-4600
published 2016-04-14CVE-2011-4600: The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when…
PriorityP335medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
1.78%
75.8th percentile
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libvirt | < libvirt 0.9.9-1 (bookworm) | libvirt 0.9.9-1 (bookworm) |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 0.9.9-1 | 0.9.9-1 |
| redhat | libvirt | >= 0 < 0.9.9-1 | 0.9.9-1 |
| redhat | libvirt | >= 0 < 0.9.9-1 | 0.9.9-1 |
| redhat | libvirt | >= 0 < 0.9.9-1 | 0.9.9-1 |
| redhat | libvirt | >= 0 < 1.2.2-0ubuntu13.1.16 | 1.2.2-0ubuntu13.1.16 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2016-01-12·CVSS 5.9
CVE-2011-4600 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
It was discovered that libvirt incorrectly handled the firewall rules on
bridge networks when the daemon was restarted. This could result in an
unintended firewall configuration. This issue only applied to Ubuntu 12.04
LTS. (CVE-2011-4600)
Peter Krempa discovered that libvirt incorrectly handled locking when
certain ACL checks failed. A local attacker could use this issue to cause
libvirt to stop responding, resulting in a denial of service. This issue
only applied to Ubuntu 14.04 LTS. (CVE-2014-8136)
Luyao Huang discovered that libvirt incorrectly handled VNC passwords in
shapshot and image files. A remote authenticated user could use this issue
to possibly obtain VNC passwords. This issue only affe
Red Hat
libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network
vendor_redhat·2011-12-09·CVSS 5.9
CVE-2011-4600 [MEDIUM] libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network
libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
Statement: This issue affect Red Hat Enterprise Linux 6 and has been addressed via
https://rhn.redhat.com/errata/RHBA-2012-0013.html. Red Hat Enterprise Linux 5 is
not affected. The Red Hat Security Response Team has rated this issue as having
low security impact. For additional information, refer to the Issue Severity
Classification: https://access.redhat.com/security/updates/classification/.
P
Debian
CVE-2011-4600: libvirt - The networkReloadIptablesRules function in network/bridge_driver.c in libvirt be...
vendor_debian·2011·CVSS 5.9
CVE-2011-4600 [MEDIUM] CVE-2011-4600: libvirt - The networkReloadIptablesRules function in network/bridge_driver.c in libvirt be...
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
Scope: local
bookworm: resolved (fixed in 0.9.9-1)
bullseye: resolved (fixed in 0.9.9-1)
forky: resolved (fixed in 0.9.9-1)
sid: resolved (fixed in 0.9.9-1)
trixie: resolved (fixed in 0.9.9-1)
GHSA
GHSA-r2xr-35cg-68vv: The networkReloadIptablesRules function in network/bridge_driver
ghsa_unreviewed·2022-05-17
CVE-2011-4600 [MEDIUM] CWE-284 GHSA-r2xr-35cg-68vv: The networkReloadIptablesRules function in network/bridge_driver
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
OSV
CVE-2011-4600: The networkReloadIptablesRules function in network/bridge_driver
osv·2016-04-14·CVSS 5.9
CVE-2011-4600 [MEDIUM] CVE-2011-4600: The networkReloadIptablesRules function in network/bridge_driver
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
OSV
libvirt vulnerabilities
osv·2016-01-12·CVSS 5.9
CVE-2011-4600 [MEDIUM] libvirt vulnerabilities
libvirt vulnerabilities
It was discovered that libvirt incorrectly handled the firewall rules on
bridge networks when the daemon was restarted. This could result in an
unintended firewall configuration. This issue only applied to Ubuntu 12.04
LTS. (CVE-2011-4600)
Peter Krempa discovered that libvirt incorrectly handled locking when
certain ACL checks failed. A local attacker could use this issue to cause
libvirt to stop responding, resulting in a denial of service. This issue
only applied to Ubuntu 14.04 LTS. (CVE-2014-8136)
Luyao Huang discovered that libvirt incorrectly handled VNC passwords in
shapshot and image files. A remote authenticated user could use this issue
to possibly obtain VNC passwords. This issue only affected Ubuntu 14.04
LTS. (CVE-2015-0236)
Han Han discovered that
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4600 libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network [fedora-16]
bugzilla·2011-12-10·CVSS 5.9
CVE-2011-4600 [MEDIUM] CVE-2011-4600 libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network [fedora-16]
CVE-2011-4600 libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network [fedora-16]
fedora-16 tracking bug for libvirt: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
The following upstream commit needs to be backported to F16:
commit ae1232b298323dd7bef909426e2ebafa6bca9157
Author: Laine Stump
Date: Tue Dec 6 15:13:50 2011 -0500
network: don't add iptables rules for externally managed networks
---
libvirt-0.9.6-4.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/libvirt-0.9.6-4.fc16
---
Package libvirt-0.9.6-4
Bugzilla
CVE-2011-4600 libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network
bugzilla·2011-12-09·CVSS 5.9
CVE-2011-4600 [MEDIUM] CVE-2011-4600 libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network
CVE-2011-4600 libvirt: unintended firewall port exposure after restarting libvirtd when defining a bridged forward-mode network
It was reported [1] that libvirt 0.9.4, if a libvirt network with "forward mode" set to "bridge" is defined and started, and libvirtd is subequently restarted, then it will insert the following iptables rules based on the bridge (assuming the bridge name is br3):
-A INPUT -i br3 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -i br3 -p tcp -m tcp --dport 53 -c -j ACCEPT
-A INPUT -i br3 -p udp -m udp --dport 67 -j ACCEPT
-A INPUT -i br3 -p tcp -m tcp --dport 67 -j ACCEPT
-A FORWARD -i br3 -o br3 -j ACCEPT
-A FORWARD -o br3 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i br3 -j REJECT --reject-with icmp-port-unreachable
An example libvirt configuration:
http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=ae1232b298323dd7bef909426e2ebafa6bca9157http://libvirt.org/news-2012.htmlhttp://www.ubuntu.com/usn/USN-2867-1https://bugzilla.redhat.com/show_bug.cgi?id=760442http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=ae1232b298323dd7bef909426e2ebafa6bca9157http://libvirt.org/news-2012.htmlhttp://www.ubuntu.com/usn/USN-2867-1https://bugzilla.redhat.com/show_bug.cgi?id=760442
2016-04-14
Published