Rapid7 Vulnerability & Exploit Database

RHSA-2011:0586: libguestfs security, bug fix, and enhancement update

Back to Search

RHSA-2011:0586: libguestfs security, bug fix, and enhancement update

Severity
5
CVSS
(AV:L/AC:M/Au:N/C:C/I:N/A:N)
Published
11/04/2010
Created
07/25/2018
Added
06/02/2011
Modified
07/04/2017

Description

libguestfs is a library for accessing and modifying guest disk images.libguestfs relied on the format auto-detection in QEMU rather thanallowing the guest image file format to be specified. A privileged guestuser could potentially use this flaw to read arbitrary files on the hostthat were accessible to a user on that host who was running a program thatutilized the libguestfs library. (CVE-2010-3851)This erratum upgrades libguestfs to upstream version 1.7.17, which includesa number of bug fixes and one enhancement. Documentation for these bugfixes and this enhancement is provided in the Technical Notes document,linked to in the References section.All libguestfs users are advised to upgrade to these updated packages,which correct this issue, and fix the bugs and add the enhancement notedin the Technical Notes.

Solution(s)

  • redhat-upgrade-guestfish
  • redhat-upgrade-libguestfs
  • redhat-upgrade-libguestfs-debuginfo
  • redhat-upgrade-libguestfs-devel
  • redhat-upgrade-libguestfs-java
  • redhat-upgrade-libguestfs-java-devel
  • redhat-upgrade-libguestfs-javadoc
  • redhat-upgrade-libguestfs-mount
  • redhat-upgrade-libguestfs-tools
  • redhat-upgrade-libguestfs-tools-c
  • redhat-upgrade-ocaml-libguestfs
  • redhat-upgrade-ocaml-libguestfs-devel
  • redhat-upgrade-perl-sys-guestfs
  • redhat-upgrade-python-libguestfs
  • redhat-upgrade-ruby-libguestfs

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;