Novell Home

CVE-2008-5086

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-5086 at MITRE

Description

Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.

NVD CVSS v2 Base Score: 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entry: 459009

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T
SUSE Linux Enterprise Desktop 10 SP2 for x86
  • libvirt >= 0.3.3-18.11
  • libvirt-python >= 0.3.3-18.11
sle10-sp2-sdk.x86-64
sled10-sp2.x86
sles10-sp2.x86-64
sled10-sp2.x86-64
sles10-sp2.x86
sles10-sp2-debuginfo.x86
sle10-sp2-sdk.x86
sles10-sp2-debuginfo.x86-64
ZYPP Patch Nr: 5869
SUSE Linux Enterprise 10 SP2 DEBUGINFO for AMD64 and Intel EM64T
SUSE Linux Enterprise 10 SP2 DEBUGINFO for x86
  • libvirt-debuginfo >= 0.3.3-18.11
sle10-sp2-sdk.x86-64
sled10-sp2.x86
sles10-sp2.x86-64
sled10-sp2.x86-64
sles10-sp2.x86
sles10-sp2-debuginfo.x86
sle10-sp2-sdk.x86
sles10-sp2-debuginfo.x86-64
ZYPP Patch Nr: 5869
SUSE Linux Enterprise Server 10 SP2 for AMD64 and Intel EM64T
SUSE Linux Enterprise Server 10 SP2 for x86
  • libvirt >= 0.3.3-18.11
  • libvirt-devel >= 0.3.3-18.11
  • libvirt-python >= 0.3.3-18.11
sle10-sp2-sdk.x86-64
sled10-sp2.x86
sles10-sp2.x86-64
sled10-sp2.x86-64
sles10-sp2.x86
sles10-sp2-debuginfo.x86
sle10-sp2-sdk.x86
sles10-sp2-debuginfo.x86-64
ZYPP Patch Nr: 5869
openSUSE 10.3
  • libvirt >= 0.3.0-30.7
  • libvirt-devel >= 0.3.0-30.7
  • libvirt-doc >= 0.3.0-30.7
  • libvirt-python >= 0.3.0-30.7

© 2012 Novell