Vulnerability Name: | CVE-2014-5177 (CCN-95277) | ||||||||||||||||||||
Assigned: | 2014-05-06 | ||||||||||||||||||||
Published: | 2014-05-06 | ||||||||||||||||||||
Updated: | 2019-04-22 | ||||||||||||||||||||
Summary: | libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. Note: this issue was SPLIT from CVE-2014-0179 per ADT3 due to different affected versions of some vectors. | ||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 1.2 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N) 0.9 Low (Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
1.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
2.4 Low (REDHAT Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-20 CWE-611 | ||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-5177 Source: CONFIRM Type: UNKNOWN http://libvirt.org/news.html Source: SUSE Type: UNKNOWN openSUSE-SU-2014:0650 Source: SUSE Type: UNKNOWN openSUSE-SU-2014:0674 Source: REDHAT Type: UNKNOWN RHSA-2014:0560 Source: CCN Type: RHSA-2014-0914 Moderate: libvirt security and bug fix update Source: SECUNIA Type: UNKNOWN 60895 Source: GENTOO Type: UNKNOWN GLSA-201412-04 Source: CCN Type: Libvirt Security Notice: LSN-2014-0003 Unsafe parsing of XML documents allows arbitrary file read Source: CONFIRM Type: Patch, Vendor Advisory http://security.libvirt.org/2014/0003.html Source: CCN Type: BID-69033 libvirt XML External Entity CVE-2014-5177 Multiple Information Disclosure Vulnerabilities Source: UBUNTU Type: UNKNOWN USN-2366-1 Source: XF Type: UNKNOWN libvirt-cve20145177-info-disc(95277) Source: CCN Type: WhiteSource Vulnerability Database CVE-2014-5177 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |