CVE Database
/

CVE-2014-0179

Back to search

CVE-2014-0179

Published: Aug 3, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT per ADT3 due to different affected versions of some vectors. CVE-2014-5177 is used for other API methods.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2014:0560
vendor-advisory
x_refsource_REDHAT
http://libvirt.org/news.html
x_refsource_CONFIRM
60895
third-party-advisory
x_refsource_SECUNIA
GLSA-201412-04
vendor-advisory
x_refsource_GENTOO
openSUSE-SU-2014:0674
vendor-advisory
x_refsource_SUSE
DSA-3038
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2014:0650
vendor-advisory
x_refsource_SUSE
USN-2366-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now