api: disallow virDomainManagedSaveDefineXML on read-only connections
The virDomainManagedSaveDefineXML can be used to alter the domain's config used for managedsave or even execute arbitrary emulator binaries. Forbid it on read-only connections. Fixes: CVE-2019-10166 Reported-by: NMatthias Gerstner <mgerstner@suse.de> Signed-off-by: NJán Tomko <jtomko@redhat.com> Reviewed-by: NDaniel P. Berrangé <berrange@redhat.com>
Showing
-
mentioned in commit e7d9c889
-
mentioned in commit d9a1f3de
-
mentioned in commit 3f744efe
-
mentioned in commit 1813138f
-
mentioned in commit 9816854a
-
mentioned in commit e777cce0
-
mentioned in commit d025c10d
-
mentioned in commit 00e673c9
-
mentioned in commit 6da721ea
-
mentioned in commit 6dc29a17
-
mentioned in commit 0a744e15
-
mentioned in commit a064d492
-
mentioned in commit 58c7c3fc
-
mentioned in commit 96bca3af
-
mentioned in commit f4dabe99
想要评论请 注册 或 登录