The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
http://libvirt.org/git/?p=libvirt.git;a=commitdiff;h=3e745e8f775dfe6f64f18b5c2fe4791b35d3546b
http://lists.opensuse.org/opensuse-updates/2014-10/msg00014.html
http://lists.opensuse.org/opensuse-updates/2014-10/msg00017.html
http://rhn.redhat.com/errata/RHSA-2014-1352.html
http://secunia.com/advisories/60291
http://secunia.com/advisories/60895
http://security.gentoo.org/glsa/glsa-201412-04.xml
http://security.libvirt.org/2014/0004.html
OR
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:lts:*:*:*:*:*
OR
cpe:2.3:a:libvirt:libvirt:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:*:*:*:*:*:*:*:* versions up to 1.2.8 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
82368 | Mandriva Linux Security Advisory : libvirt (MDVSA-2015:115) | Nessus | Mandriva Local Security Checks | medium |
81481 | SuSE 11.3 Security Update : kvm and libvirt (SAT Patch Number 10222) | Nessus | SuSE Local Security Checks | high |
81480 | SuSE 11.3 Security Update : kvm and libvirt (SAT Patch Number 10222) | Nessus | SuSE Local Security Checks | high |
79814 | GLSA-201412-04 : libvirt: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
79397 | Fedora 20 : libvirt-1.1.3.8-1.fc20 (2014-15228) | Nessus | Fedora Local Security Checks | medium |
79372 | Oracle Linux 6 : libvirt (ELSA-2014-1873) | Nessus | Oracle Linux Local Security Checks | medium |
79338 | CentOS 6 : libvirt (CESA-2014:1873) | Nessus | CentOS Local Security Checks | medium |
79331 | Scientific Linux Security Update : libvirt on SL6.x i386/x86_64 (20141118) | Nessus | Scientific Linux Local Security Checks | medium |
79329 | RHEL 6 : libvirt (RHSA-2014:1873) | Nessus | Red Hat Local Security Checks | medium |
78451 | openSUSE Security Update : libvirt (openSUSE-SU-2014:1290-1) | Nessus | SuSE Local Security Checks | medium |
78450 | openSUSE Security Update : libvirt (openSUSE-SU-2014:1293-1) | Nessus | SuSE Local Security Checks | medium |
78062 | Mandriva Linux Security Advisory : libvirt (MDVSA-2014:195) | Nessus | Mandriva Local Security Checks | medium |
78043 | CentOS 7 : libvirt (CESA-2014:1352) | Nessus | CentOS Local Security Checks | medium |
78023 | RHEL 7 : libvirt (RHSA-2014:1352) | Nessus | Red Hat Local Security Checks | medium |
78022 | Oracle Linux 7 : libvirt (ELSA-2014-1352) | Nessus | Oracle Linux Local Security Checks | medium |
78010 | Ubuntu 10.04 LTS / 12.04 LTS / 14.04 LTS : libvirt vulnerabilities (USN-2366-1) | Nessus | Ubuntu Local Security Checks | medium |
77921 | Debian DSA-3038-1 : libvirt - security update | Nessus | Debian Local Security Checks | medium |