CVE Database
/

CVE-2013-6458

Back to search

CVE-2013-6458

Published: Jan 24, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple race conditions in the (1) virDomainBlockStats, (2) virDomainGetBlockInf, (3) qemuDomainBlockJobImpl, and (4) virDomainGetBlockIoTune functions in libvirt before 1.2.1 do not properly verify that the disk is attached, which allows remote read-only attackers to cause a denial of service (libvirtd crash) via the virDomainDetachDeviceFlags command.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-2093-1
vendor-advisory
x_refsource_UBUNTU
56446
third-party-advisory
x_refsource_SECUNIA
DSA-2846
vendor-advisory
x_refsource_DEBIAN
http://libvirt.org/news.html
x_refsource_CONFIRM
60895
third-party-advisory
x_refsource_SECUNIA
GLSA-201412-04
vendor-advisory
x_refsource_GENTOO
openSUSE-SU-2014:0268
vendor-advisory
x_refsource_SUSE
RHSA-2014:0103
vendor-advisory
x_refsource_REDHAT
56186
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2014:0270
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now