Redhat

Libvirt

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Veröffentlicht 13.11.2014 21:32:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

  • EPSS 0.11%
  • Veröffentlicht 03.08.2014 18:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the ...

  • EPSS 0.11%
  • Veröffentlicht 03.08.2014 18:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompa...

  • EPSS 0.07%
  • Veröffentlicht 07.05.2014 10:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and li...

  • EPSS 0.28%
  • Veröffentlicht 15.04.2014 23:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virD...

  • EPSS 0.1%
  • Veröffentlicht 24.01.2014 18:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) ...

  • EPSS 0.14%
  • Veröffentlicht 24.01.2014 18:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibl...

  • EPSS 0.89%
  • Veröffentlicht 24.01.2014 18:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote rea...

  • EPSS 11.68%
  • Veröffentlicht 24.01.2014 18:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.

  • EPSS 0.07%
  • Veröffentlicht 07.01.2014 19:55:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to cause a denial of service (NULL pointer dereference ...