Lucene search

K
cveRedhatCVE-2014-3633
HistoryOct 06, 2014 - 2:55 p.m.

CVE-2014-3633

2014-10-0614:55:10
CWE-119
redhat
web.nvd.nist.gov
50
cve-2014-3633
qemu
qemudomaingetblockiotune
denial of service
crash
sensitive information disclosure
out-of-bounds read

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

AI Score

8

Confidence

High

EPSS

0.039

Percentile

92.0%

The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.

Affected configurations

Nvd
Node
canonicalubuntu_linuxMatch10.04lts
OR
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
Node
libvirtlibvirtRange1.2.8
OR
libvirtlibvirtMatch1.2.0
OR
libvirtlibvirtMatch1.2.1
OR
libvirtlibvirtMatch1.2.2
OR
libvirtlibvirtMatch1.2.3
OR
libvirtlibvirtMatch1.2.4
OR
libvirtlibvirtMatch1.2.5
OR
libvirtlibvirtMatch1.2.6
OR
libvirtlibvirtMatch1.2.7
VendorProductVersionCPE
canonicalubuntu_linux14.04cpe:/o:canonical:ubuntu_linux:14.04::lts:
canonicalubuntu_linux12.04cpe:/o:canonical:ubuntu_linux:12.04:::
canonicalubuntu_linux10.04cpe:/o:canonical:ubuntu_linux:10.04:::

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

AI Score

8

Confidence

High

EPSS

0.039

Percentile

92.0%