CVE-2014-3633
published 2014-10-06CVE-2014-3633: The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows…
PriorityP425medium5.8CVSS 2.0
AVNACMAuNCPINAP
EPSS
2.75%
84.6th percentile
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libvirt | < libvirt 1.2.8-2 (bookworm) | libvirt 1.2.8-2 (bookworm) |
| libvirt | libvirt | <= 1.2.8 | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| libvirt | libvirt | — | — |
| redhat | libvirt | >= 0 < 1.2.8-2 | 1.2.8-2 |
| redhat | libvirt | >= 0 < 1.2.8-2 | 1.2.8-2 |
| redhat | libvirt | >= 0 < 1.2.8-2 | 1.2.8-2 |
| redhat | libvirt | >= 0 < 1.2.8-2 | 1.2.8-2 |
| redhat | libvirt | >= 0 < 1.2.2-0ubuntu13.1.5 | 1.2.2-0ubuntu13.1.5 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-09-30·CVSS 1.9
CVE-2014-0179 [LOW] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Daniel P. Berrange and Richard Jones discovered that libvirt incorrectly
handled XML documents containing XML external entity declarations. An
attacker could use this issue to cause libvirtd to crash, resulting in a
denial of service on all affected releases, or possibly read arbitrary
files if fine grained access control was enabled on Ubuntu 14.04 LTS.
(CVE-2014-0179, CVE-2014-5177)
Luyao Huang discovered that libvirt incorrectly handled certain blkiotune
queries. An attacker could use this issue to cause libvirtd to crash,
resulting in a denial of service. This issue only applied to Ubuntu 12.04
LTS and Ubuntu 14.04 LTS. (CVE-2014-3633)
Instructions: After a standard system update you need to rebo
Red Hat
libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index
vendor_redhat·2014-09-17·CVSS 5.8
CVE-2014-3633 [MEDIUM] CWE-125 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index
libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
An out-of-bounds read flaw was found in the way libvirt's qemuDomainGetBlockIoTune() function looked up the disk index in a non-persistent (live) disk configuration while a persistent disk configuration was being indexed. A remote attacker able to establish a read-only connection to libvirtd could use this flaw to crash libvirtd or, potentially, leak memory from the libvirtd process.
Sta
Debian
CVE-2014-3633: libvirt - The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1....
vendor_debian·2014·CVSS 5.8
CVE-2014-3633 [MEDIUM] CVE-2014-3633: libvirt - The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1....
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 1.2.8-2)
bullseye: resolved (fixed in 1.2.8-2)
forky: resolved (fixed in 1.2.8-2)
sid: resolved (fixed in 1.2.8-2)
trixie: resolved (fixed in 1.2.8-2)
GHSA
GHSA-gq49-7wvq-p22q: The qemuDomainGetBlockIoTune function in qemu/qemu_driver
ghsa_unreviewed·2022-05-17
CVE-2014-3633 [MEDIUM] CWE-119 GHSA-gq49-7wvq-p22q: The qemuDomainGetBlockIoTune function in qemu/qemu_driver
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
OSV
CVE-2014-3633: The qemuDomainGetBlockIoTune function in qemu/qemu_driver
osv·2014-10-06·CVSS 5.8
CVE-2014-3633 [MEDIUM] CVE-2014-3633: The qemuDomainGetBlockIoTune function in qemu/qemu_driver
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
OSV
libvirt vulnerabilities
osv·2014-09-30·CVSS 1.9
CVE-2014-0179 [LOW] libvirt vulnerabilities
libvirt vulnerabilities
Daniel P. Berrange and Richard Jones discovered that libvirt incorrectly
handled XML documents containing XML external entity declarations. An
attacker could use this issue to cause libvirtd to crash, resulting in a
denial of service on all affected releases, or possibly read arbitrary
files if fine grained access control was enabled on Ubuntu 14.04 LTS.
(CVE-2014-0179, CVE-2014-5177)
Luyao Huang discovered that libvirt incorrectly handled certain blkiotune
queries. An attacker could use this issue to cause libvirtd to crash,
resulting in a denial of service. This issue only applied to Ubuntu 12.04
LTS and Ubuntu 14.04 LTS. (CVE-2014-3633)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3633 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index [fedora-all]
bugzilla·2014-11-05·CVSS 5.8
CVE-2014-3633 [MEDIUM] CVE-2014-3633 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index [fedora-all]
CVE-2014-3633 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2014-3633 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index
bugzilla·2014-09-12·CVSS 5.8
CVE-2014-3633 [MEDIUM] CVE-2014-3633 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index
CVE-2014-3633 libvirt: qemu: out-of-bounds read access in qemuDomainGetBlockIoTune() due to invalid index
It was found that when a disk is attached to a disk "live" (thus not
written into the persistent configuration) and then the statistics for
the disks are requested from the persistent configuration, index to
the array is determined from the live configuration but used in the
persistent.
A remote attacker able to establish a read-only connection to libvirtd
could use this flaw to crash libvirtd or, potentially, leak memory from
the libvirtd process.
Acknowledgements:
This issue was discovered by Luyao Huang of Red Hat.
Discussion:
Statement:
This issue does not affect the versions of libvirt packages as shipped with
Red Hat Enterprise Linux 5.
This issue does affect the versions
http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=3e745e8f775dfe6f64f18b5c2fe4791b35d3546bhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00014.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1352.htmlhttp://secunia.com/advisories/60291http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2014/0004.htmlhttp://www.debian.org/security/2014/dsa-3038http://www.ubuntu.com/usn/USN-2366-1http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=3e745e8f775dfe6f64f18b5c2fe4791b35d3546bhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00014.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00017.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1352.htmlhttp://secunia.com/advisories/60291http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2014/0004.htmlhttp://www.debian.org/security/2014/dsa-3038http://www.ubuntu.com/usn/USN-2366-1
2014-10-06
Published