CVE Vulnerabilities

CVE-2014-8131

Published: Jan 06, 2015 | Modified: Jan 06, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
1.8 LOW
AV:A/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.

Affected Software

Name Vendor Start Version End Version
Libvirt Redhat * 1.2.10 (including)
Libvirt Ubuntu upstream *
Libvirt Ubuntu utopic *

References