CVE-2014-5177
Summary
| CVE | CVE-2014-5177 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-03 18:55:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT from CVE-2014-0179 per ADT3 due to different affected versions of some vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:H/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Opensuse | Opensuse | 12.3 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Application | Redhat | Enterprise Virtualization | 3.0 | All | All | All |
| Application | Redhat | Libvirt | 1.0.0 | All | All | All |
| Application | Redhat | Libvirt | 1.0.1 | All | All | All |
| Application | Redhat | Libvirt | 1.0.2 | All | All | All |
| Application | Redhat | Libvirt | 1.0.3 | All | All | All |
| Application | Redhat | Libvirt | 1.0.4 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.1 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.2 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.3 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.4 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.5 | All | All | All |
| Application | Redhat | Libvirt | 1.0.5.6 | All | All | All |
| Application | Redhat | Libvirt | 1.0.6 | All | All | All |
| Application | Redhat | Libvirt | 1.1.0 | All | All | All |
| Application | Redhat | Libvirt | 1.1.1 | All | All | All |
| Application | Redhat | Libvirt | 1.1.2 | All | All | All |
| Application | Redhat | Libvirt | 1.1.3 | All | All | All |
| Application | Redhat | Libvirt | 1.1.4 | All | All | All |
| Application | Redhat | Libvirt | 1.2.0 | All | All | All |
| Application | Redhat | Libvirt | 1.2.1 | All | All | All |
| Application | Redhat | Libvirt | 1.2.2 | All | All | All |
| Application | Redhat | Libvirt | 1.2.3 | All | All | All |
| Application | Redhat | Libvirt | 1.2.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA60895 - Gentoo update for libvirt - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- libvirt: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Libvirt Security Notice: LSN-2014-0003 | af854a3a-2127-422b-91ae-364da2661108 | security.libvirt.org | Patch, Vendor Advisory |
| libvirt: Releases | af854a3a-2127-422b-91ae-364da2661108 | libvirt.org | |
| USN-2366-1: libvirt vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| openSUSE-SU-2014:0650-1: moderate: libvirt: Fixed unsafe parsing of XML | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2014:0674-1: moderate: libvirt: Fix migration with QEMU 1.6 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.