USN-2404-1

Source
https://ubuntu.com/security/notices/USN-2404-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2404-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2404-1
Related
Published
2014-11-11T16:32:45.453381Z
Modified
2014-11-11T16:32:45.453381Z
Summary
libvirt vulnerabilities
Details

Pavel Hrdina discovered that libvirt incorrectly handled locking when processing the virConnectListAllDomains command. An attacker could use this issue to cause libvirtd to hang, resulting in a denial of service. (CVE-2014-3657)

Eric Blake discovered that libvirt incorrectly handled permissions when processing the qemuDomainFormatXML command. An attacker with read-only privileges could possibly use this to gain access to certain information from the domain xml file. (CVE-2014-7823)

References

Affected packages

Ubuntu:14.04:LTS / libvirt

Package

Name
libvirt
Purl
pkg:deb/ubuntu/libvirt?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.2-0ubuntu13.1.7

Affected versions

1.*

1.1.1-0ubuntu8
1.1.1-0ubuntu9
1.1.4-0ubuntu2
1.1.4-0ubuntu3
1.1.4-0ubuntu4
1.1.4-0ubuntu5
1.2.0-0ubuntu1
1.2.0-0ubuntu2
1.2.0-0ubuntu3
1.2.1-0ubuntu1
1.2.1-0ubuntu2
1.2.1-0ubuntu3
1.2.1-0ubuntu4
1.2.1-0ubuntu5
1.2.1-0ubuntu7
1.2.1-0ubuntu8
1.2.1-0ubuntu9
1.2.1-0ubuntu10
1.2.2-0ubuntu1
1.2.2-0ubuntu2
1.2.2-0ubuntu3
1.2.2-0ubuntu4
1.2.2-0ubuntu5
1.2.2-0ubuntu6
1.2.2-0ubuntu7
1.2.2-0ubuntu8
1.2.2-0ubuntu9
1.2.2-0ubuntu10
1.2.2-0ubuntu11
1.2.2-0ubuntu12
1.2.2-0ubuntu13
1.2.2-0ubuntu13.1
1.2.2-0ubuntu13.1.1
1.2.2-0ubuntu13.1.2
1.2.2-0ubuntu13.1.4
1.2.2-0ubuntu13.1.5
1.2.2-0ubuntu13.1.6

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.2.2-0ubuntu13.1.7",
            "binary_name": "libvirt-bin"
        },
        {
            "binary_version": "1.2.2-0ubuntu13.1.7",
            "binary_name": "libvirt-dev"
        },
        {
            "binary_version": "1.2.2-0ubuntu13.1.7",
            "binary_name": "libvirt-doc"
        },
        {
            "binary_version": "1.2.2-0ubuntu13.1.7",
            "binary_name": "libvirt0"
        },
        {
            "binary_version": "1.2.2-0ubuntu13.1.7",
            "binary_name": "libvirt0-dbg"
        }
    ]
}