CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:N/I:N/A:P
EPSS
Percentile
5.1%
The storageVolUpload function in storage/storage_driver.c in libvirt before
1.2.11 does not check a certain return value, which allows local users to
cause a denial of service (NULL pointer dereference and daemon crash) via a
crafted offset value in a “virsh vol-upload” command.
libvirt.org/git/?p=libvirt.git;a=commit;h=87b9437f8951f9d24f9a85c6bbfff0e54df8c984
secunia.com/advisories/61111
security.libvirt.org/2014/0009.html
launchpad.net/bugs/cve/CVE-2014-8135
nvd.nist.gov/vuln/detail/CVE-2014-8135
security-tracker.debian.org/tracker/CVE-2014-8135
www.cve.org/CVERecord?id=CVE-2014-8135