Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libvirt | Libvirt | 0.3.2 (including) | 0.3.2 (including) |
| Libvirt | Libvirt | 0.3.3 (including) | 0.3.3 (including) |
| Libvirt | Libvirt | 0.4.1 (including) | 0.4.1 (including) |
| Libvirt | Libvirt | 0.4.2 (including) | 0.4.2 (including) |
| Libvirt | Libvirt | 0.4.6 (including) | 0.4.6 (including) |
| Libvirt | Libvirt | 0.5.0 (including) | 0.5.0 (including) |
| Libvirt | Libvirt | 0.5.1 (including) | 0.5.1 (including) |
| Red Hat Enterprise Linux 5 | RedHat | libvirt-0:0.3.3-14.el5_3.1 | * |
| Libvirt | Ubuntu | devel | * |
| Libvirt | Ubuntu | gutsy | * |
| Libvirt | Ubuntu | hardy | * |
| Libvirt | Ubuntu | intrepid | * |
| Libvirt | Ubuntu | upstream | * |