7.2
CVSSv2

CVE-2008-5086

Published: 19/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple methods in libvirt 0.3.2 up to and including 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.

Vulnerable Product Search on Vulmon Subscribe to Product

libvirt libvirt 0.5.0

libvirt libvirt 0.5.1

libvirt libvirt 0.3.2

libvirt libvirt 0.4.1

libvirt libvirt 0.3.3

libvirt libvirt 0.4.2

libvirt libvirt 0.4.6

Vendor Advisories

Synopsis Moderate: libvirt security update Type/Severity Security Advisory: Moderate Topic Updated libvirt packages that fix two security issues are now available forRed Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team[Updated 5th May ...
It was discovered that libvirt did not mark certain operations as read-only A local attacker may be able to perform privileged actions such as migrating virtual machines, adjusting autostart flags, or accessing privileged data in the virtual machine memory and disks ...