Redhat

Libvirt

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 09.12.2013 16:36:46
  • Zuletzt bearbeitet 11.04.2025 00:51:21

virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environment variables or command-line arguments.

  • EPSS 1.46%
  • Veröffentlicht 02.11.2013 18:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted X...

  • EPSS 0.02%
  • Veröffentlicht 03.10.2013 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2)...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.

  • EPSS 0.58%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via unspecified vectors involving "multiple events registration."

Exploit
  • EPSS 0.64%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows remote attackers to cause a denial of service (daemon crash) via a cpu count request, as demonstrated by the "virsh vcpucount dom -...

Exploit
  • EPSS 0.73%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated ...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The xenDaemonListDefinedDomains function in xen/xend_internal.c in libvirt 1.1.1 allows remote authenticated users to cause a denial of service (memory corruption and crash) via vectors involving the virConnectListDefinedDomains API function.

  • EPSS 0.05%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.

  • EPSS 0.07%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.