High severity7.8NVD Advisory· Published Jul 5, 2019· Updated Jun 17, 2026
CVE-2019-13314
CVE-2019-13314
Description
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- virt-bootstrap/virt-bootstrapdescription
- Range: =1.1.0
- Range: =1.1.0
- cpe:2.3:a:redhat:virt-bootstrap:1.1.0:*:*:*:*:*:*:*
- osv-coords4 versionspkg:rpm/opensuse/virt-bootstrap&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/virt-bootstrap&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/virt-bootstrap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1pkg:rpm/suse/virt-bootstrap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2
< 1.0.0-lp152.5.3.1+ 3 more
- (no CPE)range: < 1.0.0-lp152.5.3.1
- (no CPE)range: < 1.0.0-lp151.4.3.1
- (no CPE)range: < 1.0.0-5.3.124
- (no CPE)range: < 1.0.0-5.3.124
Patches
Vulnerability mechanics
References
7- www.redhat.com/archives/virt-tools-list/2019-July/msg00043.htmlnvdExploitMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2019/07/08/3nvdThird Party Advisory
- github.com/virt-manager/virt-bootstrap/releasesnvdRelease NotesThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-10/msg00080.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-11/msg00026.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2PQSLGSTPVQ5WQ4DDKFV4I262JIFXY6/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKMQLYAHCDIE5TBXWDNBG7554KWI5QT3/nvd
News mentions
0No linked articles in our index yet.