CVE-2014-3657

MEDIUM

Description

The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.

References

http://libvirt.org/git/?p=libvirt.git;a=commitdiff;h=fc22b2e74890873848b43fffae43025d22053669

http://lists.opensuse.org/opensuse-updates/2014-10/msg00014.html

http://lists.opensuse.org/opensuse-updates/2014-10/msg00017.html

http://rhn.redhat.com/errata/RHSA-2014-1352.html

http://secunia.com/advisories/60291

http://secunia.com/advisories/62303

http://security.libvirt.org/2014/0005.html

http://www.ubuntu.com/usn/USN-2404-1

Details

Source: MITRE

Published: 2014-10-06

Updated: 2014-11-19

Type: CWE-399

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Tenable Plugins

View all (15 total)

IDNameProductFamilySeverity
82368Mandriva Linux Security Advisory : libvirt (MDVSA-2015:115)NessusMandriva Local Security Checks
medium
81481SuSE 11.3 Security Update : kvm and libvirt (SAT Patch Number 10222)NessusSuSE Local Security Checks
high
81480SuSE 11.3 Security Update : kvm and libvirt (SAT Patch Number 10222)NessusSuSE Local Security Checks
high
79397Fedora 20 : libvirt-1.1.3.8-1.fc20 (2014-15228)NessusFedora Local Security Checks
medium
79372Oracle Linux 6 : libvirt (ELSA-2014-1873)NessusOracle Linux Local Security Checks
medium
79338CentOS 6 : libvirt (CESA-2014:1873)NessusCentOS Local Security Checks
medium
79331Scientific Linux Security Update : libvirt on SL6.x i386/x86_64 (20141118)NessusScientific Linux Local Security Checks
medium
79329RHEL 6 : libvirt (RHSA-2014:1873)NessusRed Hat Local Security Checks
medium
79210Ubuntu 14.04 LTS / 14.10 : libvirt vulnerabilities (USN-2404-1)NessusUbuntu Local Security Checks
medium
78451openSUSE Security Update : libvirt (openSUSE-SU-2014:1290-1)NessusSuSE Local Security Checks
medium
78450openSUSE Security Update : libvirt (openSUSE-SU-2014:1293-1)NessusSuSE Local Security Checks
medium
78062Mandriva Linux Security Advisory : libvirt (MDVSA-2014:195)NessusMandriva Local Security Checks
medium
78043CentOS 7 : libvirt (CESA-2014:1352)NessusCentOS Local Security Checks
medium
78023RHEL 7 : libvirt (RHSA-2014:1352)NessusRed Hat Local Security Checks
medium
78022Oracle Linux 7 : libvirt (ELSA-2014-1352)NessusOracle Linux Local Security Checks
medium