VulnerabilityModified
CVE-2019-3886
The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
MEDIUM 5.4EPSS 1.11%
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- redhat/libvirt · opensuse/leap · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/107777Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:3723Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886Exploit, Issue Tracking, Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/
- https://usn.ubuntu.com/4021-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00105.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/107777Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:3723Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3886Exploit, Issue Tracking, Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CYMNKXAUBZCFBBPFH64FJPH5EJH4GSU2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R5DHYIFECZ7BMVXK4EP4FDFZXK7I5MZH/
- https://usn.ubuntu.com/4021-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.