rpm package
suse/libvirt&distro=SUSE Linux Enterprise Point of Sale 11 SP3
pkg:rpm/suse/libvirt&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-10161 | — | < 1.0.5.9-21.20.1 | 1.0.5.9-21.20.1 | Jul 30, 2019 | It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirt | ||
| CVE-2018-3639 | — | < 1.0.5.9-21.9.1 | 1.0.5.9-21.9.1 | May 22, 2018 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka | ||
| CVE-2018-1064 | — | < 1.0.5.9-21.5.1 | 1.0.5.9-21.5.1 | Mar 28, 2018 | libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent. | ||
| CVE-2018-5748 | — | < 1.0.5.9-21.5.1 | 1.0.5.9-21.5.1 | Jan 25, 2018 | qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply. | ||
| CVE-2017-5715 | — | < 1.0.5.9-21.5.1 | 1.0.5.9-21.5.1 | Jan 4, 2018 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |
- CVE-2019-10161Jul 30, 2019affected < 1.0.5.9-21.20.1fixed 1.0.5.9-21.20.1
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirt
- CVE-2018-3639May 22, 2018affected < 1.0.5.9-21.9.1fixed 1.0.5.9-21.9.1
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka
- CVE-2018-1064Mar 28, 2018affected < 1.0.5.9-21.5.1fixed 1.0.5.9-21.5.1
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
- CVE-2018-5748Jan 25, 2018affected < 1.0.5.9-21.5.1fixed 1.0.5.9-21.5.1
qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.
- CVE-2017-5715Jan 4, 2018affected < 1.0.5.9-21.5.1fixed 1.0.5.9-21.5.1
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.