Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2014-1447 from the MITRE CVE dictionary dictionary and NIST NVD.
Not vulnerable. This issue did not affect the versions of libvirt as shipped with Red Hat Enterprise Linux 5.
Base Score | 3.3 |
---|---|
Base Metrics | AV:A/AC:L/Au:N/C:N/I:N/A:P |
Access Vector | Adjacent Network |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | None |
Availability Impact | Partial |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux 6 (libvirt) | RHSA-2014:0103 | 2014-01-28 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux 7 | libvirt | Will not fix |
Red Hat Enterprise Linux 5 | libvirt | Not affected |