Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 241146 (CVE-2008-4405) - app-emulation/libvirt privilege escalation (CVE-2008-4405,CVE-2008-5716)
Summary: app-emulation/libvirt privilege escalation (CVE-2008-4405,CVE-2008-5716)
Status: RESOLVED FIXED
Alias: CVE-2008-4405
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa]
Keywords:
: 252731 (view as bug list)
Depends on:
Blocks:
 
Reported: 2008-10-10 19:29 UTC by Stefan Behte (RETIRED)
Modified: 2009-11-07 06:35 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-10-10 19:29:44 UTC
CVE-2008-4405 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4405):
  libvirt 0.3.3 relies on files located under subdirectories of
  /local/domain in xenstore despite lack of protection against
  modification by Xen guest virtual machines, which allows guest OS
  users to have an unspecified impact, as demonstrated by writing to
  (1) the text console (console/tty) or (2) the VNC port for the
  graphical framebuffer.
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-12-27 19:51:49 UTC
The patch is incomplete, as noted here:
http://thread.gmane.org/gmane.comp.security.oss.general/1344/

This incomplete patch has been assigned CVE-2008-5716.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-12-27 19:52:36 UTC
*** Bug 252731 has been marked as a duplicate of this bug. ***
Comment 4 Doug Goldstein (RETIRED) gentoo-dev 2009-05-27 22:50:41 UTC
Can this be closed? the oldest version in the tree is 0.4.6
Comment 5 Doug Goldstein (RETIRED) gentoo-dev 2009-06-09 13:36:19 UTC
Oldest version in the tree is now 0.6.3. Looking for some follow up from the security team since it's their bug.
Comment 6 Stefan Behte (RETIRED) gentoo-dev Security 2009-11-07 06:33:19 UTC
Closing noglsa, as it never had a stable version.