Severity
7.8HIGH
EPSS
0.3%
top 50.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 30
Latest updateMay 24

Description

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

NVDredhat/libvirt5.0.05.4.1+1
Debianlibvirt< 5.0.0-4+3
CVEListV5libvirt/libvirtfixed in 4.10.1, fixed in 5.4.1+1

Also affects: Ubuntu Linux 14.04, Enterprise Linux 6.0, 7.0, 8.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6cwp-pxj6-56c7: It was discovered that libvirtd before versions 42022-05-24
OSV
CVE-2019-10161: It was discovered that libvirtd before versions 42019-07-30
CVEList
CVE-2019-10161: It was discovered that libvirtd before versions 42019-07-30

📋Vendor Advisories

4
Ubuntu
libvirt update vulnerability2020-01-13
Ubuntu
libvirt vulnerabilities2019-07-08
Red Hat
libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API2019-06-20
Debian
CVE-2019-10161: libvirt - It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit re...2019

💬Community

3
Bugzilla
CVE-2019-10161 mingw-libvirt: libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API [fedora-all]2019-06-20
Bugzilla
CVE-2019-10161 libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API [fedora-all]2019-06-20
Bugzilla
CVE-2019-10161 libvirt: arbitrary file read/exec via virDomainSaveImageGetXMLDesc API2019-06-13
CVE-2019-10161 (HIGH CVSS 7.8) | It was discovered that libvirtd bef | cvebase.io