Lucene search

K
nvd[email protected]NVD:CVE-2014-3633
HistoryOct 06, 2014 - 2:55 p.m.

CVE-2014-3633

2014-10-0614:55:10
CWE-119
web.nvd.nist.gov
5

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

AI Score

7.8

Confidence

High

EPSS

0.039

Percentile

92.0%

The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.

Affected configurations

Nvd
Node
canonicalubuntu_linuxMatch10.04lts
OR
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
Node
libvirtlibvirtRange1.2.8
OR
libvirtlibvirtMatch1.2.0
OR
libvirtlibvirtMatch1.2.1
OR
libvirtlibvirtMatch1.2.2
OR
libvirtlibvirtMatch1.2.3
OR
libvirtlibvirtMatch1.2.4
OR
libvirtlibvirtMatch1.2.5
OR
libvirtlibvirtMatch1.2.6
OR
libvirtlibvirtMatch1.2.7

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

AI Score

7.8

Confidence

High

EPSS

0.039

Percentile

92.0%