CVE-2019-3886
Publication date 4 April 2019
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
Status
Package | Ubuntu Release | Status |
---|---|---|
libvirt | ||
20.04 LTS focal |
Fixed 5.4.0-0ubuntu1
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
Notes
Patch details
Package | Patch details |
---|---|
libvirt |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.4 · Medium |
Attack vector | Adjacent |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | Low |
Integrity impact | None |
Availability impact | Low |
Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
References
Related Ubuntu Security Notices (USN)
- USN-4021-1
- libvirt vulnerabilities
- 19 June 2019