First published: Wed Mar 09 2011(Updated: )
Description of problem: It has been found that several libvirt API calls (virNodeDeviceDettach, virNodeDeviceReset, virNodeDeviceReAttach, virDomainRevertToSnapshot, virDomainSnapshotDelete and virConnectDomainXMLToNative) did not honour read-only connection. Local attacker could use this flaw to crash the server (DoS) or possibly escalate his privileges.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Libvirt-daemon-driver-storage-iscsi-direct | =0.8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1146 has a medium severity rating due to the potential for local attackers to exploit the flaw.
To fix CVE-2011-1146, you should upgrade to a patched version of libvirt that addresses this vulnerability.
CVE-2011-1146 specifically affects libvirt version 0.8.8.
CVE-2011-1146 could allow local attackers to perform unauthorized actions on the libvirt API.
CVE-2011-1146 affects multiple libvirt API calls including virNodeDeviceDetach and virDomainSnapshotDelete.