CVE-2008-5086
Published Dec 19, 2008
Last updated 7 years ago
Overview
- Description
- Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:libvirt:libvirt:0.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E86FE3D-BC93-49DE-8D34-61C17072D190" }, { "criteria": "cpe:2.3:a:libvirt:libvirt:0.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB95BD9D-A6B5-47B9-B2B0-9C4CC67BA62F" }, { "criteria": "cpe:2.3:a:libvirt:libvirt:0.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4DA90AC2-B415-42F5-86E5-9564F4133A53" }, { "criteria": "cpe:2.3:a:libvirt:libvirt:0.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29FBE340-26FF-4D72-99C3-423786A2095B" }, { "criteria": "cpe:2.3:a:libvirt:libvirt:0.4.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "01BFB306-AF97-460F-9D26-9CF53018280D" }, { "criteria": "cpe:2.3:a:libvirt:libvirt:0.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D5D9844D-5B89-4B47-9E38-BDF0C44D1BAB" }, { "criteria": "cpe:2.3:a:libvirt:libvirt:0.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E4BA9E6F-7F06-4341-928A-5CE6C5EAAA7A" } ], "operator": "OR" } ] } ]