CVE-2010-2239 describes a vulnerability in Red Hat libvirt, specifically versions 0.6.0 through 0.8.2, where the creation of new virtual machine images fails to properly set the user-defined backing-store format. This oversight allows authenticated guest OS users to potentially read arbitrary files on the host operating system through unspecified vectors. The vulnerability has a CVSS score of 4.4 (AV:L/AC:M/Au:S/C:C/I:N/A:N), indicating a low attack complexity requiring local access and user authentication, with a high impact on confidentiality. While it allows for arbitrary file reading, it does not directly impact integrity or availability. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The CVE has garnered minimal community discussion and media coverage, suggesting it is not a widely recognized or actively targeted threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.6.0CPE matchmatch criteria | cpe:2.3:a:libvirt:libvirt:0.6.0:*:*:*:*:*:*:* | ||
0.6.1CPE matchmatch criteria | cpe:2.3:a:libvirt:libvirt:0.6.1:*:*:*:*:*:*:* | ||
0.6.2CPE matchmatch criteria | cpe:2.3:a:libvirt:libvirt:0.6.2:*:*:*:*:*:*:* | ||
0.6.3CPE matchmatch criteria | cpe:2.3:a:libvirt:libvirt:0.6.3:*:*:*:*:*:*:* | ||
0.6.4CPE matchmatch criteria | cpe:2.3:a:libvirt:libvirt:0.6.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:S/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.