CVE-2019-3886
CVE-2019-3886
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 1.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
04 Apr 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Affected products
The libvirt Project · libvirtWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.htmlhttps://access.redhat.com/errata/RHBA-2019:3723https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/https://usn.ubuntu.com/4021-1/http://www.securityfocus.com/bid/107777