libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libvirt | Redhat | * | 1.3.1 (excluding) |
Libvirt | Ubuntu | esm-infra-legacy/trusty | * |
Libvirt | Ubuntu | precise/esm | * |
Libvirt | Ubuntu | trusty | * |
Libvirt | Ubuntu | trusty/esm | * |
Libvirt | Ubuntu | upstream | * |