Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2011-2178

The virSecurityManagerGetPrivateData function in security/security_manager.c in libvirt 0.8.8 through 0.9.1 uses the wrong argument for a sizeof call, which causes incorrect processing of "security manager private data" that "reopens disk probing" and might allow guest OS users to read arbitrary files on the host OS. NOTE: this vulnerability exists because of a CVE-2010-2238 regression.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.4%
CVSS Severity
CVSS v2 Score 4.4
References
Products affected by CVE-2011-2178
  • Redhat » Libvirt » Version: 0.8.8
    cpe:2.3:a:redhat:libvirt:0.8.8
  • Redhat » Libvirt » Version: 0.9.0
    cpe:2.3:a:redhat:libvirt:0.9.0
  • Redhat » Libvirt » Version: 0.9.1
    cpe:2.3:a:redhat:libvirt:0.9.1


Contact Us

Shodan ® - All rights reserved