First published: Wed Aug 05 2020(Updated: )
A vulnerability was found in libvirt, where an incorrect permissions on the UNIX domain socket. A local attacker could use this issue to access libvirt and escalate privileges. References: <a href="https://bugs.mageia.org/27038">https://bugs.mageia.org/27038</a>
Credit: security@ubuntu.com security@ubuntu.com security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libvirt | 7.0.0-3+deb11u3 9.0.0-4+deb12u1 10.8.0-1 10.9.0-1 | |
Ubuntu Linux | =20.04 | |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15708 is considered a high-severity vulnerability due to the potential for privilege escalation by a local attacker.
To fix CVE-2020-15708, ensure that libvirt is updated to a fixed version as specified in the security advisories.
CVE-2020-15708 affects libvirt versions in certain Debian and Ubuntu distributions.
CVE-2020-15708 cannot be exploited remotely as it requires local access to the system.
The nature of CVE-2020-15708 involves incorrect permissions on the UNIX domain socket, allowing unauthorized access to libvirt.