Описание
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1.2.8-0ubuntu14 |
esm-infra-legacy/trusty | released | 1.2.2-0ubuntu13.1.7 |
lucid | not-affected | 0.7.5-5ubuntu27.24 |
precise | not-affected | 0.9.8-2ubuntu17.20 |
trusty | released | 1.2.2-0ubuntu13.1.7 |
trusty/esm | released | 1.2.2-0ubuntu13.1.7 |
upstream | needs-triage | |
utopic | released | 1.2.8-0ubuntu11.1 |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
The virDomainListPopulate function in conf/domain_conf.c in libvirt be ...
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
ELSA-2014-1352: libvirt security and bug fix update (MODERATE)
EPSS
5 Medium
CVSS2