First published: Thu Jun 24 2010(Updated: )
It was found that libvirt did not extract the defined disk backing store format when recursing into disk image backing stores in the security drivers. This could be possibly exploited by priviledged guest user to access arbitrary files on the host.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
libvirt | =0.7.2 | |
libvirt | =0.7.3 | |
libvirt | =0.7.4 | |
libvirt | =0.7.5 | |
libvirt | =0.7.6 | |
libvirt | =0.7.7 | |
libvirt | =0.8.0 | |
libvirt | =0.8.1 | |
libvirt | =0.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2238 is classified as a high-severity vulnerability due to its potential to allow privileged guest users to access arbitrary files on the host system.
To mitigate CVE-2010-2238, you should upgrade libvirt to version 0.8.3 or later, which contains the necessary security patches.
CVE-2010-2238 affects libvirt versions from 0.7.2 to 0.8.2.
CVE-2010-2238 can potentially be exploited by privileged guest users within the virtualized environment.
The impact of CVE-2010-2238 is that it allows unauthorized access to sensitive files on the host from a compromised virtual machine.