USN-4047-1: libvirt vulnerabilities
Matthias Gerstner and Ján Tomko discovered that libvirt incorrectly handled certain API calls. An attacker could possibly use this issue to check for arbitrary files, or execute arbitrary binaries. In the default installation, attackers would be isolated by the libvirt AppArmor profile.
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this security advisory?
The vulnerability ID for this security advisory is USN-4047-1.
What is the severity of USN-4047-1?
The severity of USN-4047-1 is not specified in the security advisory.
How does this vulnerability affect the libvirt software on Ubuntu 19.04?
This vulnerability affects the libvirt software on Ubuntu 19.04 if it is running version 5.0.0-1ubuntu2.4 or earlier of libvirt-clients, libvirt-daemon, or libvirt0.
What is the remedy for this vulnerability on Ubuntu 18.04?
The remedy for this vulnerability on Ubuntu 18.04 is to upgrade to version 4.0.0-1ubuntu8.12 or later of libvirt-clients, libvirt-daemon, or libvirt0.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following references: [CVE-2019-10161](https://ubuntu.com/security/CVE-2019-10161), [CVE-2019-10166](https://ubuntu.com/security/CVE-2019-10166), [CVE-2019-10167](https://ubuntu.com/security/CVE-2019-10167).