CVE-2008-5086

Aliases:DEBIAN-CVE-2008-5086
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 19 Dec 2008, 17:00
Last modified:07 Aug 2024, 10:40

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.2 HIGH
v2.0 (nvd)
EPSS Score
0.38% LOW
0% probability +0.34%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Dec 2008, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 10:40
Last Modified
Vulnerability information updated

Description

Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.

CVSS Metrics

  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.38% Percentile: 32%

Affected Systems

  • debianlibvirt

    < 0.4.6-10 | < 0.4.6-10 | < 0.4.6-10 | < 0.4.6-10

  • libvirtlibvirt

    0.3.2 | 0.3.3 | 0.4.1 | 0.4.2 | 0.4.6 | 0.5.0 | 0.5.1

References (14)