Описание
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1.2.8-0ubuntu6 |
esm-infra-legacy/trusty | released | 1.2.2-0ubuntu13.1.5 |
lucid | not-affected | |
precise | released | 0.9.8-2ubuntu17.20 |
trusty | released | 1.2.2-0ubuntu13.1.5 |
trusty/esm | released | 1.2.2-0ubuntu13.1.5 |
upstream | needed |
Показывать по
EPSS
5.8 Medium
CVSS2
Связанные уязвимости
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt ...
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
ELSA-2014-1352: libvirt security and bug fix update (MODERATE)
EPSS
5.8 Medium
CVSS2