CVE-2010-2242
Last modified
CVE-2010-2242 is a vulnerability of currently unknown severity. Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directory tree.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libvirt | Libvirt | 0.2.0 |
| Libvirt | Libvirt | 0.2.1 |
| Libvirt | Libvirt | 0.2.2 |
| Libvirt | Libvirt | 0.2.3 |
| Libvirt | Libvirt | 0.3.0 |
| Libvirt | Libvirt | 0.3.1 |
| Libvirt | Libvirt | 0.3.2 |
| Libvirt | Libvirt | 0.3.3 |
| Libvirt | Libvirt | 0.4.0 |
| Libvirt | Libvirt | 0.4.1 |
| Libvirt | Libvirt | 0.4.2 |
| Libvirt | Libvirt | 0.4.3 |
| Libvirt | Libvirt | 0.4.4 |
| Libvirt | Libvirt | 0.4.6 |
| Libvirt | Libvirt | 0.5.0 |
| Libvirt | Libvirt | 0.5.1 |
| Libvirt | Libvirt | 0.6.0 |
| Libvirt | Libvirt | 0.6.1 |
| Libvirt | Libvirt | 0.6.2 |
| Libvirt | Libvirt | 0.6.3 |
| Libvirt | Libvirt | 0.6.4 |
| Libvirt | Libvirt | 0.6.5 |
| Libvirt | Libvirt | 0.7.0 |
| Libvirt | Libvirt | 0.7.1 |
| Libvirt | Libvirt | 0.7.2 |
| Libvirt | Libvirt | 0.7.3 |
| Libvirt | Libvirt | 0.7.4 |
| Libvirt | Libvirt | 0.7.5 |
| Libvirt | Libvirt | 0.7.6 |
| Libvirt | Libvirt | 0.7.7 |
| Libvirt | Libvirt | 0.8.0 |
| Libvirt | Libvirt | 0.8.1 |
| Libvirt | Libvirt | 0.8.2 |
References
- http://libvirt.org/news.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2010/2062Vendor Advisory
- http://libvirt.org/news.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2010/2062Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-2242?
How severe is CVE-2010-2242?
How do I fix CVE-2010-2242?
Are you affected by CVE-2010-2242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
