Vulnerabilities
Vulnerable Software
Libvirt:  >> Libvirt  >> 1.2.5  Security Vulnerabilities
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.
CVSS Score
5.8
EPSS Score
0.036
Published
2014-10-06
The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.
CVSS Score
5.0
EPSS Score
0.015
Published
2014-10-06


Contact Us

Shodan ® - All rights reserved