Unrated severityOSV Advisory· Published Apr 18, 2019· Updated Aug 6, 2024
CVE-2016-10746
CVE-2016-10746
Description
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
Affected products
3- osv-coords2 versionspkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/suse/libvirt-python&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS
< 1.2.5-23.24.1+ 1 more
- (no CPE)range: < 1.2.5-23.24.1
- (no CPE)range: < 1.2.5-3.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/libvirt/libvirt/commit/506e9d6c2d4baaf580d489fff0690c0ff2ff588fmitrex_refsource_MISC
- github.com/libvirt/libvirt/compare/11288f5...8fd6867mitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2019/04/msg00032.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.