PT-2015-4011 · Qemu+1 · Libvirt+1

Martin Kletzander

·

Publicado

2014-12-18

·

Atualizado

2024-06-15

·

CVE-2014-8131

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libvirt versions prior to 1.2.11
Description The issue arises from the qemu implementation of virConnectGetAllDomainStats in libvirt, which fails to handle locks correctly when a domain is skipped due to ACL restrictions. This allows remote authenticated users to cause a denial of service, resulting in a deadlock or segmentation fault and crash, by making a request to access domains they do not have privileges to access.
Recommendations For versions prior to 1.2.11, update to version 1.2.11 or later to resolve the issue.

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2472
CVE-2014-8131
OPENSUSE-SU-2024:10209-1

Produtos afetados

Alt Linux
Libvirt