Redhat

Libvirt

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.82%
  • Veröffentlicht 13.07.2016 15:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

  • EPSS 0.03%
  • Veröffentlicht 25.05.2016 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.

  • EPSS 0.49%
  • Veröffentlicht 14.04.2016 15:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS po...

  • EPSS 0.31%
  • Veröffentlicht 14.04.2016 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restriction...

  • EPSS 0.06%
  • Veröffentlicht 11.04.2016 21:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not doma...

  • EPSS 0.65%
  • Veröffentlicht 29.01.2015 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interf...

  • EPSS 0.37%
  • Veröffentlicht 06.01.2015 15:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segme...

  • EPSS 0.13%
  • Veröffentlicht 19.12.2014 15:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 19.12.2014 15:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted offset value in ...

  • EPSS 0.68%
  • Veröffentlicht 12.12.2014 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) b...