PT-2014-4186 · Red Hat+3 · Libvirt+4

Published

2014-01-24

·

Updated

2024-06-15

·

CVE-2014-1447

CVSS v2.0

3.3

Low

VectorAV:A/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libvirt versions prior to 1.2.1
Description The issue is related to a race condition in the virNetServerClientStartKeepAlive function. This allows remote attackers to cause a denial of service by closing a connection before a keepalive response is sent, resulting in a crash of libvirtd.
Recommendations For versions prior to 1.2.1, update to version 1.2.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the virNetServerClientStartKeepAlive function to minimize the risk of exploitation.

Fix

DoS

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1262
CESA-2014_0103
CVE-2014-1447
DSA-2846-1
MGASA-2014-0051
OPENSUSE-SU-2024:10209-1
RHSA-2014:0103
RHSA-2014_0103

Affected Products

Alt Linux
Centos
Red Hat
Suse
Libvirt