CVE-2014-1447
published 2014-01-24CVE-2014-1447: Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash)…
PriorityP413low3.3CVSS 2.0
AVAACLAuNCNINAP
EPSS
2.34%
81.8th percentile
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
Affected
115 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.2.1-1 (bookworm) | libvirt 1.2.1-1 (bookworm) |
| redhat | libvirt | <= 1.2.0 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
CVSS provenance
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-01-30·CVSS 2.1
CVE-2013-6436 [LOW] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Martin Kletzander discovered that libvirt incorrectly handled reading
memory tunables from LXC guests. A local user could possibly use this flaw
to cause libvirtd to crash, resulting in a denial of service. This issue
only affected Ubuntu 13.10. (CVE-2013-6436)
Dario Faggioli discovered that libvirt incorrectly handled the libxl
driver. A local user could possibly use this flaw to cause libvirtd to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 13.10. (CVE-2013-6457)
It was discovered that libvirt contained multiple race conditions in block
device handling. A remote read-only user could use this flaw to cause
libvirtd to crash, resulting i
Debian
CVE-2014-1447: libvirt - Race condition in the virNetServerClientStartKeepAlive function in libvirt befor...
vendor_debian·2014·CVSS 3.3
CVE-2014-1447 [LOW] CVE-2014-1447: libvirt - Race condition in the virNetServerClientStartKeepAlive function in libvirt befor...
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
Scope: local
bookworm: resolved (fixed in 1.2.1-1)
bullseye: resolved (fixed in 1.2.1-1)
forky: resolved (fixed in 1.2.1-1)
sid: resolved (fixed in 1.2.1-1)
trixie: resolved (fixed in 1.2.1-1)
Red Hat
libvirt: denial of service with keepalive
vendor_redhat·2013-12-31·CVSS 3.3
CVE-2014-1447 [LOW] libvirt: denial of service with keepalive
libvirt: denial of service with keepalive
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
Statement: Not vulnerable. This issue did not affect the versions of libvirt as shipped with Red Hat Enterprise Linux 5.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Affected
GHSA
GHSA-35qx-m8hh-rrjv: Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1
ghsa_unreviewed·2022-05-17
CVE-2014-1447 [LOW] CWE-362 GHSA-35qx-m8hh-rrjv: Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
OSV
CVE-2014-1447: Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1
osv·2014-01-24·CVSS 3.3
CVE-2014-1447 [LOW] CVE-2014-1447: Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1447 libvirt: denial of service with keepalive [fedora-all]
bugzilla·2014-01-17·CVSS 3.3
CVE-2014-1447 [LOW] CVE-2014-1447 libvirt: denial of service with keepalive [fedora-all]
CVE-2014-1447 libvirt: denial of service with keepalive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mult
Bugzilla
CVE-2014-1447 libvirt: denial of service with keepalive
bugzilla·2014-01-14·CVSS 3.3
CVE-2014-1447 [LOW] CVE-2014-1447 libvirt: denial of service with keepalive
CVE-2014-1447 libvirt: denial of service with keepalive
A race condition was found in the way libvirtd handled keepalive initialization requests when the connection is closed prior to establishing connection credentials.
An attacker able to establish a read-only connection to libvirtd could use this flaw to crash libvirtd, resulting in a denial of service.
Upstream patches:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=173c291
http://libvirt.org/git/?p=libvirt.git;a=commit;h=066c8ef
Discussion:
Statement:
Not vulnerable. This issue did not affect the versions of libvirt as shipped with Red Hat Enterprise Linux 5.
---
CVE Request --
http://seclists.org/oss-sec/2014/q1/82
---
Created libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1054808]
---
This issue has be
http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00060.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00062.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0103.htmlhttp://secunia.com/advisories/56321http://secunia.com/advisories/56446http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.debian.org/security/2014/dsa-2846http://www.securitytracker.com/id/1029695http://www.ubuntu.com/usn/USN-2093-1https://bugzilla.redhat.com/show_bug.cgi?id=1047577http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00060.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00062.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0103.htmlhttp://secunia.com/advisories/56321http://secunia.com/advisories/56446http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://www.debian.org/security/2014/dsa-2846http://www.securitytracker.com/id/1029695http://www.ubuntu.com/usn/USN-2093-1https://bugzilla.redhat.com/show_bug.cgi?id=1047577
2014-01-24
Published