CVE-2015-5160
20.08.2018, 21:29
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libvirt | libvirt | 𝑥 < 2.2 |
| redhat | virtualization | 3.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_eus | 7.3 |
| redhat | enterprise_linux_eus | 7.4 |
| redhat | enterprise_linux_eus | 7.5 |
| redhat | enterprise_linux_eus | 7.6 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_server_eus | 7.4 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_server_tus | 7.3 |
| redhat | enterprise_linux_server_tus | 7.6 |
| redhat | enterprise_linux_workstation | 7.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| libvirt |
| ||
| libvirt-client |
| ||
| libvirt-daemon |
| ||
| libvirt-daemon-config-network |
| ||
| libvirt-daemon-config-nwfilter |
| ||
| libvirt-daemon-driver-interface |
| ||
| libvirt-daemon-driver-lxc |
| ||
| libvirt-daemon-driver-network |
| ||
| libvirt-daemon-driver-nodedev |
| ||
| libvirt-daemon-driver-nwfilter |
| ||
| libvirt-daemon-driver-qemu |
| ||
| libvirt-daemon-driver-secret |
| ||
| libvirt-daemon-driver-storage |
| ||
| libvirt-daemon-kvm |
| ||
| libvirt-daemon-lxc |
| ||
| libvirt-devel |
| ||
| libvirt-docs |
| ||
| libvirt-lock-sanlock |
| ||
| libvirt-login-shell |
| ||
| libvirt-nss |
|
Common Weakness Enumeration
References