CVE-2014-3633
Published: 19 September 2014
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
Priority
Status
Package | Release | Status |
---|---|---|
libvirt Launchpad, Ubuntu, Debian |
upstream |
Needed
|
lucid |
Not vulnerable
|
|
precise |
Released
(0.9.8-2ubuntu17.20)
|
|
trusty |
Released
(1.2.2-0ubuntu13.1.5)
|
|
Patches: upstream: http://libvirt.org/git/?p=libvirt.git;a=commit;h=3e745e8f775dfe6f64f18b5c2fe4791b35d3546b |