Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-3657

Опубликовано: 06 окт. 2014
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:libvirt:libvirt:*:*:*:*:*:*:*:*
Версия до 1.2.8 (включая)
cpe:2.3:a:libvirt:libvirt:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.7:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01497
Низкий

5 Medium

CVSS2

Дефекты

CWE-399

Связанные уязвимости

ubuntu
почти 11 лет назад

The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.

redhat
почти 11 лет назад

The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.

debian
почти 11 лет назад

The virDomainListPopulate function in conf/domain_conf.c in libvirt be ...

github
больше 3 лет назад

The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.

oracle-oval
почти 11 лет назад

ELSA-2014-1352: libvirt security and bug fix update (MODERATE)

EPSS

Процентиль: 80%
0.01497
Низкий

5 Medium

CVSS2

Дефекты

CWE-399