what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 1 of 1 RSS Feed

Files

Ubuntu Security Notice 1008-1
Posted Oct 22, 2010
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 1008-1 - It was discovered that libvirt would probe disk backing stores without consulting the defined format for the disk. A privileged attacker in the guest could exploit this to read arbitrary files on the host. This issue only affected Ubuntu 10.04 LTS. By default, guests are confined by an AppArmor profile which provided partial protection against this flaw. It was discovered that libvirt would create new VMs without setting a backing store format. A privileged attacker in the guest could exploit this to read arbitrary files on the host. This issue did not affect Ubuntu 8.04 LTS. In Ubuntu 9.10 and later guests are confined by an AppArmor profile which provided partial protection against this flaw. Jeremy Nickurak discovered that libvirt created iptables rules with too lenient mappings of source ports. A privileged attacker in the guest could bypass intended restrictions to access privileged resources on the host.

tags | advisory, arbitrary
systems | linux, ubuntu
advisories | CVE-2010-2237, CVE-2010-2238, CVE-2010-2239, CVE-2010-2242
SHA-256 | c064ab38868a95bbd59b13f2896302bf08bc54ede0f09b2e2a8362053a7462e5
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Deepfakes Of Victims Used In Sextortion Attacks Spike, FBI Warns
Posted Jun 7, 2023

tags | headline, privacy, cybercrime, fraud, fbi
BBC, BA, And Boots Issued With Ultimatum By Cyber Gang Clop
Posted Jun 7, 2023

tags | headline, hacker, malware, britain, data loss, cryptography
What's Really Changed 10 Years After The Snowden Revelations
Posted Jun 7, 2023

tags | headline, government, usa, russia, data loss, spyware, backdoor, nsa
ByteDance Accused Of Helping China Spy On Hong Kong Activists
Posted Jun 7, 2023

tags | headline, government, china, spyware, social
Crypto Catastrophe Stikes Some Atomic Wallet Users, Over $35 Million Thought Stolen
Posted Jun 6, 2023

tags | headline, hacker, bank, data loss, fraud, cryptography
Microsoft To Pay $20m For Child Privacy Violations
Posted Jun 6, 2023

tags | headline, government, privacy, microsoft, usa
MoveIt Hack: What Actions Can Data Breach Victims Take?
Posted Jun 6, 2023

tags | headline, hacker, data loss, flaw
SEC Accuses Coinbase Cryptocurrency Exchange Of Breaking US Regulations
Posted Jun 6, 2023

tags | headline, government, usa, fraud, cryptography
Ransomware Attacks Have Room To Grow, Verizon Report Shows
Posted Jun 6, 2023

tags | headline, hacker, data loss, cryptography
U.S. Senate Leader Schedules Classified AI Briefings
Posted Jun 6, 2023

tags | headline, government, usa, botnet, science
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close