CVE-2019-3886

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-3886
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3886.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-3886
Related
Published
2019-04-04T16:29:03Z
Modified
2025-01-14T08:05:50.512767Z
Downstream
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVSS Calculator
Summary
[none]
Details

An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.

References

Affected packages

Debian:11 / libvirt

Package

Name
libvirt
Purl
pkg:deb/debian/libvirt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-2

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / libvirt

Package

Name
libvirt
Purl
pkg:deb/debian/libvirt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-2

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / libvirt

Package

Name
libvirt
Purl
pkg:deb/debian/libvirt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-2

Ecosystem specific

{
    "urgency": "low"
}

Git / github.com/libvirt/libvirt

Affected ranges

Type
GIT
Repo
https://github.com/libvirt/libvirt
Events

Affected versions

v4.*

v4.10.0
v4.10.0-rc1
v4.10.0-rc2
v4.8.0
v4.9.0
v4.9.0-rc1

v5.*

v5.0.0
v5.0.0-rc1
v5.0.0-rc2
v5.1.0
v5.1.0-rc1
v5.1.0-rc2
v5.2.0
v5.2.0-rc1
v5.2.0-rc2
v5.3.0-rc1
v5.3.0-rc2