CVE-2019-10167

Publication date 20 June 2019

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

7.8 · High

Score breakdown

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary path for this argument, causing libvirtd to execute a crafted executable with its own privileges.

Status

Package Ubuntu Release Status
libvirt 19.10 eoan
Fixed 5.4.0-0ubuntu3
19.04 disco
Fixed 5.0.0-1ubuntu2.4
18.10 cosmic
Fixed 4.6.0-2ubuntu3.8
18.04 LTS bionic
Fixed 4.0.0-1ubuntu8.12
16.04 LTS xenial
Fixed 1.3.1-1ubuntu10.27
14.04 LTS trusty
Not affected

Severity score breakdown

Parameter Value
Base score 7.8 · High
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H