First published: Thu Apr 18 2019(Updated: )
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libvirt | <1.3.1 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10746 is a vulnerability in libvirt that allows guest agents with an RO connection to make virDomainGetTime API calls, even when an RW connection is supposed to be required.
CVE-2016-10746 is considered high severity with a severity value of 7.5.
Libvirt versions up to, but not including, 1.3.1 on Redhat and Debian Linux version 8.0 are affected by CVE-2016-10746.
To fix CVE-2016-10746, you should update your libvirt software to version 1.3.1 or later.
You can find more information about CVE-2016-10746 at the following references: [Reference 1](https://github.com/libvirt/libvirt/commit/506e9d6c2d4baaf580d489fff0690c0ff2ff588f), [Reference 2](https://github.com/libvirt/libvirt/compare/11288f5...8fd6867), [Reference 3](https://lists.debian.org/debian-lts-announce/2019/04/msg00032.html).