cbcvebase.
CVE-2014-5177
published 2014-08-03

CVE-2014-5177: libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document…

low1.2CVSS 3.1
AVLACHAuNCPINAN
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT from CVE-2014-0179 per ADT3 due to different affected versions of some vectors.

Affected

81 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibvirt< libvirt 1.2.4-1 (bookworm)libvirt 1.2.4-1 (bookworm)
opensuseopensuse
opensuseopensuse
redhatenterprise_linux
redhatenterprise_virtualization
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt

CVSS provenance

nvd1.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW