[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-6458Date: (C)2014-01-28   (M)2023-12-22


Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 3.2
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: ADJACENT_NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECUNIA-56186
SECUNIA-56446
SECUNIA-60895
DSA-2846
GLSA-201412-04
RHSA-2014:0103
USN-2093-1
http://libvirt.org/news.html
https://bugzilla.redhat.com/show_bug.cgi?id=1043069
openSUSE-SU-2014:0268
openSUSE-SU-2014:0270

CPE    110
cpe:/a:redhat:libvirt:0.0.4
cpe:/a:redhat:libvirt:0.4.0
cpe:/a:redhat:libvirt:0.0.5
cpe:/a:redhat:libvirt:0.4.1
...
CWE    1
CWE-362
OVAL    12
oval:org.secpod.oval:def:601198
oval:org.secpod.oval:def:1500363
oval:org.secpod.oval:def:701553
oval:org.secpod.oval:def:106486
...

© SecPod Technologies