CVE-2014-5177
published 2014-08-03CVE-2014-5177: libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document…
PriorityP417low1.2CVSS 2.0
AVLACHAuNCPINAN
EPSS
0.53%
41.2th percentile
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT from CVE-2014-0179 per ADT3 due to different affected versions of some vectors.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.2.4-1 (bookworm) | libvirt 1.2.4-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_virtualization | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
CVSS provenance
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2014-09-30·CVSS 1.9
CVE-2014-0179 [LOW] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: Several security issues were fixed in libvirt.
Daniel P. Berrange and Richard Jones discovered that libvirt incorrectly
handled XML documents containing XML external entity declarations. An
attacker could use this issue to cause libvirtd to crash, resulting in a
denial of service on all affected releases, or possibly read arbitrary
files if fine grained access control was enabled on Ubuntu 14.04 LTS.
(CVE-2014-0179, CVE-2014-5177)
Luyao Huang discovered that libvirt incorrectly handled certain blkiotune
queries. An attacker could use this issue to cause libvirtd to crash,
resulting in a denial of service. This issue only applied to Ubuntu 12.04
LTS and Ubuntu 14.04 LTS. (CVE-2014-3633)
Instructions: After a standard system update you need to rebo
Red Hat
libvirt: unsafe parsing of XML documents allows libvirt DoS and/or arbitrary file read
vendor_redhat·2014-05-06·CVSS 1.9
CVE-2014-5177 [LOW] CWE-611 libvirt: unsafe parsing of XML documents allows libvirt DoS and/or arbitrary file read
libvirt: unsafe parsing of XML documents allows libvirt DoS and/or arbitrary file read
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (
Red Hat
libvirt: unsafe parsing of XML documents allows libvirt DoS and/or arbitrary file read
vendor_redhat·2014-05-06·CVSS 1.9
CVE-2014-0179 [LOW] CWE-611 libvirt: unsafe parsing of XML documents allows libvirt DoS and/or arbitrary file read
libvirt: unsafe parsing of XML documents allows libvirt DoS and/or arbitrary file read
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT per ADT3 due to different affected versions of some vectors. CVE-2014-5177 is used for other API methods.
It was found that libvirt passes the XML_PARSE_NOENT flag when parsing XML documents using the libxml2 library, in which case all XML entities in the parsed documents are expanded. A user able to force libvirtd to parse an XML documen
Debian
CVE-2014-5177: libvirt - libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is en...
vendor_debian·2014·CVSS 1.9
CVE-2014-5177 [LOW] CVE-2014-5177: libvirt - libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is en...
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCP
Debian
CVE-2014-0179: libvirt - libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of...
vendor_debian·2014·CVSS 1.9
CVE-2014-0179 [LOW] CVE-2014-0179: libvirt - libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of...
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT per ADT3 due to different affected versions of some vectors. CVE-2014-5177 is used for other API methods.
Scope: local
bookworm: resolved (fixed in 1.2.4-1)
bullseye: resolved (fixed in 1.2.4-1)
forky: resolved (fixed in 1.2.4-1)
sid: resolved (fixed in 1.2.4-1)
trixie: resolved (fixed in 1.2.4-1)
GHSA
GHSA-chq6-pgcm-wg35: libvirt 0
ghsa_unreviewed·2022-05-14·CVSS 1.2
CVE-2014-0179 [LOW] CWE-20 GHSA-chq6-pgcm-wg35: libvirt 0
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT per ADT3 due to different affected versions of some vectors. CVE-2014-5177 is used for other API methods.
GHSA
GHSA-v3jv-v62w-8q9m: libvirt 1
ghsa_unreviewed·2022-05-14·CVSS 1.9
CVE-2014-5177 [LOW] CWE-20 GHSA-v3jv-v62w-8q9m: libvirt 1
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCP
OSV
libvirt vulnerabilities
osv·2014-09-30·CVSS 1.9
CVE-2014-0179 [LOW] libvirt vulnerabilities
libvirt vulnerabilities
Daniel P. Berrange and Richard Jones discovered that libvirt incorrectly
handled XML documents containing XML external entity declarations. An
attacker could use this issue to cause libvirtd to crash, resulting in a
denial of service on all affected releases, or possibly read arbitrary
files if fine grained access control was enabled on Ubuntu 14.04 LTS.
(CVE-2014-0179, CVE-2014-5177)
Luyao Huang discovered that libvirt incorrectly handled certain blkiotune
queries. An attacker could use this issue to cause libvirtd to crash,
resulting in a denial of service. This issue only applied to Ubuntu 12.04
LTS and Ubuntu 14.04 LTS. (CVE-2014-3633)
OSV
CVE-2014-5177: libvirt 1
osv·2014-08-03·CVSS 1.9
CVE-2014-5177 [LOW] CVE-2014-5177: libvirt 1
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCP
OSV
CVE-2014-0179: libvirt 0
osv·2014-08-03·CVSS 1.9
CVE-2014-0179 [LOW] CVE-2014-0179: libvirt 0
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT per ADT3 due to different affected versions of some vectors. CVE-2014-5177 is used for other API methods.
No detection rules found.
No public exploits indexed.
http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00048.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00052.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0560.htmlhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2014/0003.htmlhttp://www.ubuntu.com/usn/USN-2366-1http://libvirt.org/news.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00048.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00052.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0560.htmlhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2014/0003.htmlhttp://www.ubuntu.com/usn/USN-2366-1
2014-08-03
Published