FS#42159 - [libvirt] CVE-2014-3633 out-of-bounds read access
            Attached to Project:
            Community Packages
            
Opened by Levente Polyak (anthraxx) - Sunday, 28 September 2014, 15:04 GMT
Last edited by Sergej Pupykin (sergej) - Monday, 29 September 2014, 11:02 GMT
          Opened by Levente Polyak (anthraxx) - Sunday, 28 September 2014, 15:04 GMT
Last edited by Sergej Pupykin (sergej) - Monday, 29 September 2014, 11:02 GMT
| 
 | Details
                    Hello, libvirt <= 1.2.8 is suffering from an out-of-bounds read access [0] in qemuDomainGetBlockIoTune() due to invalid index. A remote attacker able to establish a read-only connection to libvirtd could use this flaw to crash libvirtd or, potentially, leak memory from the libvirtd process. A fix for this flaw has been commited upstream [1] and f.e. already applied by debian [2] as 1.2.9 is not yet there. [0] https://access.redhat.com/security/cve/CVE-2014-3633 [1] http://libvirt.org/git/?p=libvirt.git;a=commit;h=3e745e8f775dfe6f64f18b5c2fe4791b35d3546b [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=762203 | 
              This task depends upon
              
              
            
            
          
            Closed by  Sergej Pupykin (sergej)
Monday, 29 September 2014, 11:02 GMT
Reason for closing: Fixed
Additional comments about closing: patch applied
          
        Monday, 29 September 2014, 11:02 GMT
Reason for closing: Fixed
Additional comments about closing: patch applied
 
                      
[0] http://libvirt.org/git/?p=libvirt.git;a=commit;h=3e745e8f775dfe6f64f18b5c2fe4791b35d3546b