CVE-2011-4600
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions…
Does this matter?
Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.
Description
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- canonical/ubuntu linux · redhat/libvirt
- Source
- secalert@redhat.com
References
- http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=ae1232b298323dd7bef909426e2ebafa6bca9157
- http://libvirt.org/news-2012.htmlVendor Advisory
- http://www.ubuntu.com/usn/USN-2867-1
- https://bugzilla.redhat.com/show_bug.cgi?id=760442
- http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=ae1232b298323dd7bef909426e2ebafa6bca9157
- http://libvirt.org/news-2012.htmlVendor Advisory
- http://www.ubuntu.com/usn/USN-2867-1
- https://bugzilla.redhat.com/show_bug.cgi?id=760442
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.