Lucene search

K
nvd[email protected]NVD:CVE-2014-3657
HistoryOct 06, 2014 - 2:55 p.m.

CVE-2014-3657

2014-10-0614:55:10
CWE-399
web.nvd.nist.gov
8

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

7.7

Confidence

High

EPSS

0.038

Percentile

91.9%

The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.

Affected configurations

Nvd
Node
libvirtlibvirtRange1.2.8
OR
libvirtlibvirtMatch1.2.0
OR
libvirtlibvirtMatch1.2.1
OR
libvirtlibvirtMatch1.2.2
OR
libvirtlibvirtMatch1.2.3
OR
libvirtlibvirtMatch1.2.4
OR
libvirtlibvirtMatch1.2.5
OR
libvirtlibvirtMatch1.2.6
OR
libvirtlibvirtMatch1.2.7

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

7.7

Confidence

High

EPSS

0.038

Percentile

91.9%