Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8136

Опубликовано: 19 дек. 2014
Источник: debian
EPSS Низкий

Описание

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libvirtfixed1.2.9-7package
libvirtnot-affectedwheezypackage
libvirtnot-affectedsqueezepackage

Примечания

  • Upstream commit: http://libvirt.org/git/?p=libvirt.git;a=commit;h=2bdcd29c713dfedd813c89f56ae98f6f3898313d (v1.2.11-rc2)

  • Introduced in http://libvirt.org/git/?p=libvirt.git;a=commitdiff;h=abf75aea247e (v1.1.0-rc1)

EPSS

Процентиль: 33%
0.00131
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

redhat
больше 10 лет назад

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

nvd
больше 10 лет назад

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

github
больше 3 лет назад

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

oracle-oval
больше 10 лет назад

ELSA-2015-0323: libvirt security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 33%
0.00131
Низкий
Уязвимость CVE-2014-8136