4.4
CVSSv2

CVE-2011-2178

Published: 10/08/2011 Updated: 07/11/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.9 | Exploitability Score: 2.7
VMScore: 392
Vector: AV:L/AC:M/Au:S/C:C/I:N/A:N

Vulnerability Summary

The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 up to and including 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 0.9.0

redhat libvirt 0.8.8

redhat libvirt 0.9.1

Vendor Advisories

Debian Bug report logs - #629128 regression in 088 reopens security issue Package: libvirt; Maintainer for libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: "Thijs Kinkhorst" <thijs@debianorg> Date: Fri, 3 Jun 2011 18:15:04 UTC Severity: serious Tags: patch Fou ...
Libvirt could be made to crash or read arbitrary files on the host ...