Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2011-1146

Published: 15 March 2011

libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.

Notes

AuthorNote
jdstrand
code not present in 8.04 LTS

Priority

Medium

Status

Package Release Status
libvirt
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Not vulnerable

karmic
Released (0.7.0-1ubuntu13.3)
lucid
Released (0.7.5-5ubuntu27.9)
maverick
Released (0.8.3-1ubuntu14.1)
upstream
Released (0.8.8-3)