First published: Tue Mar 31 2020(Updated: )
A bug was reported internally about a bug in libvirt allowing a user on a read-only to change the response timeout for all guest agent messages. Changing this timeout can potentially cause some commands to fail.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libvirt | <6.2.0 | |
redhat/libvirt | <6.2.0 | 6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10701 is a vulnerability found in the libvirt API that allows read-only connections to adjust the QEMU agent response timeout.
CVE-2020-10701 has a severity rating of 6.5 out of 10, which is considered medium.
The affected software for CVE-2020-10701 is libvirt version up to 6.2.0.
To fix CVE-2020-10701, update libvirt to version 6.2.0 or above.
You can find more information about CVE-2020-10701 in the following references: [link1], [link2], [link3].