PT-2014-1809 · Libvirt+5 · Libvirt+5

Published

2014-11-05

·

Updated

2024-06-15

·

CVE-2014-7823

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Libvirt versions prior to 1.2.11
Description The issue allows remote read-only users to obtain the VNC password by using the VIR DOMAIN XML MIGRATABLE flag, which triggers the use of the VIR DOMAIN XML SECURE flag. This can lead to a breach of confidentiality and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations As a temporary workaround, consider disabling the virDomainGetXMLDesc API until a patch is available. Update to a version of Libvirt that is 1.2.11 or later to resolve the issue. Restrict access to the vulnerable API endpoint to minimize the risk of exploitation. Avoid using the VIR DOMAIN XML MIGRATABLE flag in the affected API endpoint until the issue is resolved.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2472
BDU:2015-06009
BDU:2015-06010
BDU:2015-06011
BDU:2015-06012
BDU:2015-06013
BDU:2015-07119
BDU:2015-07120
BDU:2015-07121
BDU:2015-07122
BDU:2015-07123
BDU:2015-07124
BDU:2015-07125
BDU:2015-07126
BDU:2015-07127
BDU:2015-07128
BDU:2015-07129
BDU:2015-07130
BDU:2015-07131
BDU:2015-07132
BDU:2015-07133
BDU:2015-07134
BDU:2015-07135
BDU:2015-07136
BDU:2015-07137
BDU:2015-07138
BDU:2015-07139
BDU:2015-09147
BDU:2015-09148
BDU:2015-09149
BDU:2015-09150
BDU:2015-09151
BDU:2015-09254
BDU:2015-09255
BDU:2015-09256
BDU:2015-09257
BDU:2015-09258
BDU:2015-09259
BDU:2015-09260
BDU:2015-09261
BDU:2015-09262
BDU:2015-09263
BDU:2015-09264
BDU:2015-09265
BDU:2015-09266
BDU:2015-09267
BDU:2015-09268
BDU:2015-09269
BDU:2015-09270
BDU:2015-09271
BDU:2015-09272
BDU:2015-09273
BDU:2015-09274
CESA-2014_1873
CESA-2015_0008
CVE-2014-7823
MGASA-2014-0470
OPENSUSE-SU-2024:10209-1
RHSA-2014:1873
RHSA-2014_1873
RHSA-2015:0008
RHSA-2015_0008
SUSE-SU-2015:0241-1
SUSE-SU-2015:0357-1
USN-2404-1

Affected Products

Alt Linux
Centos
Libvirt
Red Hat
Suse
Ubuntu