CVE-2020-15708
published 2020-11-06CVE-2020-15708: Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.38%
30.6th percentile
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | libvirt | — | — |
| redhat | libvirt | >= 0 < 6.0.0-0ubuntu8.3 | 6.0.0-0ubuntu8.3 |
| ubuntu | libvirt | >= unspecified < 6.0.0-0ubuntu8.3 | 6.0.0-0ubuntu8.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_oracle9.8CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges
vendor_redhat·2020-08-04·CVSS 9.3
CVE-2020-15708 [CRITICAL] CWE-732 libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges
libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
A flaw was found in libvirt, where an incorrect permissions issue occurs on the UNIX domain socket. This flaw allows a local attacker to access libvirt and escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.
Statement: This is an Ubuntu specific flaw. The versions of `libvirt` as shipped with Red Hat Enterprise Linux and RHEL Advanced Virtualization are not affected by this issue, as they leverage `polkit` for authentication
Ubuntu
libvirt vulnerability
vendor_ubuntu·2020-08-04
CVE-2020-15708 libvirt vulnerability
Title: libvirt vulnerability
Summary: libvirt could be made to run programs as an administrator.
Trent Shea working with Trend Micro´s Zero Day Initiative, discovered that
the libvirt package set incorrect permissions on the UNIX domain socket. A
local attacker could use this issue to access libvirt and escalate
privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: User Interface (Apache Synapse) — CVE-2017-15708
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2017-15708 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: User Interface (Apache Synapse) — CVE-2017-15708
Oracle Oracle Financial Services Applications Risk Matrix: User Interface (Apache Synapse) vulnerability
CVE: CVE-2017-15708
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Portal (Apache Commons) — CVE-2017-15708
vendor_oracle·2020-01-15·CVSS 9.8
CVE-2017-15708 [CRITICAL] Oracle Oracle PeopleSoft Risk Matrix: Portal (Apache Commons) — CVE-2017-15708
Oracle Oracle PeopleSoft Risk Matrix: Portal (Apache Commons) vulnerability
CVE: CVE-2017-15708
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Debian
CVE-2020-15708: libvirt - Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world r...
vendor_debian·2020·CVSS 9.3
CVE-2020-15708 [CRITICAL] CVE-2020-15708: libvirt - Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world r...
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-6pr6-q53r-2q97: Ubuntu's packaging of libvirt in 20
ghsa_unreviewed·2022-05-24
CVE-2020-15708 [HIGH] CWE-732 GHSA-6pr6-q53r-2q97: Ubuntu's packaging of libvirt in 20
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
OSV
CVE-2020-15708: Ubuntu's packaging of libvirt in 20
osv·2020-08-04·CVSS 7.8
CVE-2020-15708 [HIGH] CVE-2020-15708: Ubuntu's packaging of libvirt in 20
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15708 mingw-libvirt: libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges [fedora-all]
bugzilla·2020-08-05·CVSS 9.3
CVE-2020-15708 [CRITICAL] CVE-2020-15708 mingw-libvirt: libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges [fedora-all]
CVE-2020-15708 mingw-libvirt: libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2020-15708 libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges [fedora-all]
bugzilla·2020-08-05·CVSS 9.3
CVE-2020-15708 [CRITICAL] CVE-2020-15708 libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges [fedora-all]
CVE-2020-15708 libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2020-15708 libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges
bugzilla·2020-08-05·CVSS 9.3
CVE-2020-15708 [CRITICAL] CVE-2020-15708 libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges
CVE-2020-15708 libvirt: incorrect permissions on the UNIX domain socket allows local attacker to escalate privileges
A vulnerability was found in libvirt, where an incorrect permissions on the UNIX domain socket. A local attacker could use this issue to access libvirt and escalate privileges.
References:
https://bugs.mageia.org/27038
Discussion:
Created libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1866271]
Created mingw-libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1866272]
---
This is an Ubuntu specific flaw because they change the libvirt defaults in their distro to disable use of polkit for authentication, without also changing the socket permissisons.
The normal upstream behaviour is that the socket is mode 0666, and when an unprivileged us
2020-11-06
Published