CVE-2014-3672: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
Published May 25, 2016
·Updated
The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
Affected Software
2 affected components
redhat libvirt<=1.2.21
XEN Xen
Event History
May 25, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3672?
CVE-2014-3672 has a high severity rating due to its potential to cause denial of service attacks through host disk consumption.
2
How do I fix CVE-2014-3672?
To fix CVE-2014-3672, upgrade libvirt to version 1.3.0 or later, as this version contains the necessary patches.
3
Which software versions are affected by CVE-2014-3672?
CVE-2014-3672 affects libvirt versions prior to 1.3.0 and certain versions of Xen.
4
What type of vulnerability is CVE-2014-3672?
CVE-2014-3672 is a local denial of service vulnerability that allows guest OS users to consume host disk space.
5
Who can exploit CVE-2014-3672?
CVE-2014-3672 can be exploited by local users on the guest operating system.