CVE-2010-2237: Medium severity oracle libvirt vulnerability
It was found that libvirt did not honour the user defined main disk format in guest XML when looking up disk backing stores in the security drivers. This could be possibly exploited by priviledged guest user to access arbitrary files on the host.
Other sources
Red Hat libvirt, possibly 0.6.1 through 0.8.2, looks up disk backing stores without referring to the user-defined main disk format, which might allow guest OS users to read arbitrary files on the host OS, and possibly have unspecified other impact, via unknown vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2237?
CVE-2010-2237 has been classified as a moderate severity vulnerability.
How do I fix CVE-2010-2237?
To fix CVE-2010-2237, update libvirt to a version later than 0.8.2.
What impact does CVE-2010-2237 have on system security?
CVE-2010-2237 allows a privileged guest user to potentially access arbitrary files on the host system.
Are there any known exploits for CVE-2010-2237?
There are no publicly known exploits for CVE-2010-2237, but the vulnerability could still be exploited by attackers.
Which versions of libvirt are affected by CVE-2010-2237?
CVE-2010-2237 affects libvirt versions from 0.6.1 to 0.8.2.