UBUNTU-CVE-2019-10161

    Dashboard / Vulnerabilities / UBUNTU-CVE-2019-10161

    UBUNTU-CVE-2019-10161

    Published: 20 Jun 2019Last Modified: 22 Apr 2026

    Summary:

    Details: It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.

    Affected packages

    Package

    Name: libvirt

    Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=trusty/esm

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.2.2-0ubuntu13.1.28+esm1

    Affected versions

    1.1.1-0ubuntu8
    1.1.1-0ubuntu9
    1.1.4-0ubuntu2
    1.1.4-0ubuntu3
    1.1.4-0ubuntu4
    1.1.4-0ubuntu5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High