First published: Thu Jun 24 2010(Updated: )
It was found that libvirt did not extract the defined disk backing store format when recursing into disk image backing stores in the security drivers. This could be possibly exploited by priviledged guest user to access arbitrary files on the host.
Affected Software | Affected Version | How to fix |
---|---|---|
libvirt |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-607811 is considered high due to the potential for privileged guest users to access arbitrary files on the host.
To fix REDHAT-BUG-607811, it is recommended to update libvirt to the latest version that addresses this flaw.
Exploiting REDHAT-BUG-607811 could allow a privileged guest user to gain unauthorized access to sensitive files on the host system.
All versions of libvirt prior to the security update that resolves REDHAT-BUG-607811 are affected.
System administrators using libvirt in environments with untrusted guest users should be particularly concerned about REDHAT-BUG-607811.