The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
http://libvirt.org/git/?p=libvirt.git;a=commitdiff;h=fc22b2e74890873848b43fffae43025d22053669
http://lists.opensuse.org/opensuse-updates/2014-10/msg00014.html
http://lists.opensuse.org/opensuse-updates/2014-10/msg00017.html
http://rhn.redhat.com/errata/RHSA-2014-1352.html
http://secunia.com/advisories/60291
http://secunia.com/advisories/62303
OR
cpe:2.3:a:libvirt:libvirt:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.4:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.5:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.6:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:1.2.7:*:*:*:*:*:*:*
cpe:2.3:a:libvirt:libvirt:*:*:*:*:*:*:*:* versions up to 1.2.8 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
82368 | Mandriva Linux Security Advisory : libvirt (MDVSA-2015:115) | Nessus | Mandriva Local Security Checks | medium |
81481 | SuSE 11.3 Security Update : kvm and libvirt (SAT Patch Number 10222) | Nessus | SuSE Local Security Checks | high |
81480 | SuSE 11.3 Security Update : kvm and libvirt (SAT Patch Number 10222) | Nessus | SuSE Local Security Checks | high |
79397 | Fedora 20 : libvirt-1.1.3.8-1.fc20 (2014-15228) | Nessus | Fedora Local Security Checks | medium |
79372 | Oracle Linux 6 : libvirt (ELSA-2014-1873) | Nessus | Oracle Linux Local Security Checks | medium |
79338 | CentOS 6 : libvirt (CESA-2014:1873) | Nessus | CentOS Local Security Checks | medium |
79331 | Scientific Linux Security Update : libvirt on SL6.x i386/x86_64 (20141118) | Nessus | Scientific Linux Local Security Checks | medium |
79329 | RHEL 6 : libvirt (RHSA-2014:1873) | Nessus | Red Hat Local Security Checks | medium |
79210 | Ubuntu 14.04 LTS / 14.10 : libvirt vulnerabilities (USN-2404-1) | Nessus | Ubuntu Local Security Checks | medium |
78451 | openSUSE Security Update : libvirt (openSUSE-SU-2014:1290-1) | Nessus | SuSE Local Security Checks | medium |
78450 | openSUSE Security Update : libvirt (openSUSE-SU-2014:1293-1) | Nessus | SuSE Local Security Checks | medium |
78062 | Mandriva Linux Security Advisory : libvirt (MDVSA-2014:195) | Nessus | Mandriva Local Security Checks | medium |
78043 | CentOS 7 : libvirt (CESA-2014:1352) | Nessus | CentOS Local Security Checks | medium |
78023 | RHEL 7 : libvirt (RHSA-2014:1352) | Nessus | Red Hat Local Security Checks | medium |
78022 | Oracle Linux 7 : libvirt (ELSA-2014-1352) | Nessus | Oracle Linux Local Security Checks | medium |