CVE-2014-0028
published 2014-01-24CVE-2014-0028: libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain…
PriorityP418medium4.3CVSS 2.0
AVAACMAuNCPINAP
EPSS
0.62%
45.9th percentile
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.2.1-1 (bookworm) | libvirt 1.2.1-1 (bookworm) |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 1.2.1-1 | 1.2.1-1 |
| redhat | libvirt | >= 0 < 1.2.1-1 | 1.2.1-1 |
| redhat | libvirt | >= 0 < 1.2.1-1 | 1.2.1-1 |
| redhat | libvirt | >= 0 < 1.2.1-1 | 1.2.1-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:A/AC:M/Au:N/C:P/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-01-30·CVSS 2.1
CVE-2013-6436 [LOW] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Martin Kletzander discovered that libvirt incorrectly handled reading
memory tunables from LXC guests. A local user could possibly use this flaw
to cause libvirtd to crash, resulting in a denial of service. This issue
only affected Ubuntu 13.10. (CVE-2013-6436)
Dario Faggioli discovered that libvirt incorrectly handled the libxl
driver. A local user could possibly use this flaw to cause libvirtd to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 13.10. (CVE-2013-6457)
It was discovered that libvirt contained multiple race conditions in block
device handling. A remote read-only user could use this flaw to cause
libvirtd to crash, resulting i
Red Hat
libvirt: event registration bypasses domain:getattr ACL
vendor_redhat·2014-01-15·CVSS 4.3
CVE-2014-0028 [MEDIUM] libvirt: event registration bypasses domain:getattr ACL
libvirt: event registration bypasses domain:getattr ACL
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.
Statement: Not vulnerable.
This issue did not affect the libvirt packages as shipped with Red Hat Enterprise Linux 5 and 6.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Will not fix
Package: libvirt (Red Hat Storage 2.0) - Not affected
Package: libvirt (Red Hat Storage 2.1) - Not affecte
Debian
CVE-2014-0028: libvirt - libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the dom...
vendor_debian·2014·CVSS 4.3
CVE-2014-0028 [MEDIUM] CVE-2014-0028: libvirt - libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the dom...
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.
Scope: local
bookworm: resolved (fixed in 1.2.1-1)
bullseye: resolved (fixed in 1.2.1-1)
forky: resolved (fixed in 1.2.1-1)
sid: resolved (fixed in 1.2.1-1)
trixie: resolved (fixed in 1.2.1-1)
GHSA
GHSA-76m6-h6vf-x33v: libvirt 1
ghsa_unreviewed·2022-05-17
CVE-2014-0028 [MEDIUM] GHSA-76m6-h6vf-x33v: libvirt 1
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.
OSV
CVE-2014-0028: libvirt 1
osv·2014-01-24·CVSS 4.3
CVE-2014-0028 [MEDIUM] CVE-2014-0028: libvirt 1
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7814 CFME: REST API SQL Injection
bugzilla·2014-10-27·CVSS 6.5
CVE-2014-7814 [MEDIUM] CVE-2014-7814 CFME: REST API SQL Injection
CVE-2014-7814 CFME: REST API SQL Injection
Aaron Patterson of Red Hat reports:
If the REST API is going to support a filter, that should be converted to an
ActiveRecord where clause - where it should be safer. In general, it would be
good to understand why we offer SQL filters on the REST API because I do not
think they should be exposed.
Discussion:
Acknowledgement:
This issue was discovered by the Red Hat CloudForms Team.
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.3
Via RHSA-2015:0028 https://rhn.redhat.com/errata/RHSA-2015-0028.html
Bugzilla
CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL [fedora-20]
bugzilla·2014-01-16·CVSS 4.3
CVE-2014-0028 [MEDIUM] CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL [fedora-20]
CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-20 tracking bug
Bugzilla
CVE-2014-0492 flash-plugin: memory address layout randomization defeat (APSB14-02)
bugzilla·2014-01-14·CVSS 10.0
CVE-2014-0492 [CRITICAL] CVE-2014-0492 flash-plugin: memory address layout randomization defeat (APSB14-02)
CVE-2014-0492 flash-plugin: memory address layout randomization defeat (APSB14-02)
Adobe has released Flash Player 11.2.202.335 for Linux to correct the following flaw:
* These updates resolve an address leak vulnerability that could be used to defeat memory address layout randomization (CVE-2014-0492).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-02.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:0028 https://rhn.redhat.com/errata/RHSA-2014-0028.html
Bugzilla
CVE-2014-0491 flash-plugin: security protection bypass (APSB14-02)
bugzilla·2014-01-14·CVSS 10.0
CVE-2014-0491 [CRITICAL] CVE-2014-0491 flash-plugin: security protection bypass (APSB14-02)
CVE-2014-0491 flash-plugin: security protection bypass (APSB14-02)
Adobe has released Flash Player 11.2.202.335 for Linux to correct the following flaw:
* These updates resolve a vulnerability that could be used to bypass Flash Player security protections (CVE-2014-0491).
External References:
http://helpx.adobe.com/security/products/flash-player/apsb14-02.html
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2014:0028 https://rhn.redhat.com/errata/RHSA-2014-0028.html
Bugzilla
CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL
bugzilla·2014-01-06·CVSS 4.3
CVE-2014-0028 [MEDIUM] CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL
CVE-2014-0028 libvirt: event registration bypasses domain:getattr ACL
Eric Blake from Red Hat reports that ever since libvirt 1.1.1 added ACL domain:getattr filtering for commands like virConnectListAllDomains, we have had a latent problem that the use of virConnectDomainEventRegister() and virConnectDomainEventRegisterAny() can be used to learn about virDomainPtr objects that should have been inaccessible to the user. It is not a problem if you are not using ACLs; also, it is partially mitigated by the fact that any domain that does not trigger an event in the timeframe where the attacker maintains their event callback will not be leaked.
Once an attacker has learned about a domain by bypassing domain:getattr, they could perform other actions on the domain if there were not ACLs to filt
http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00060.htmlhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.ubuntu.com/usn/USN-2093-1https://bugzilla.redhat.com/show_bug.cgi?id=1048637https://www.redhat.com/archives/libvir-list/2014-January/msg00684.htmlhttp://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00060.htmlhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.ubuntu.com/usn/USN-2093-1https://bugzilla.redhat.com/show_bug.cgi?id=1048637https://www.redhat.com/archives/libvir-list/2014-January/msg00684.html
2014-01-24
Published