CVE-2014-5177
Last modified
CVE-2014-5177 is a vulnerability of currently unknown severity. libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT from CVE-2014-0179 per ADT3 due to different affected versions of some vectors.. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT from CVE-2014-0179 per ADT3 due to different affected versions of some vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Virtualization | 3.0 |
| Opensuse | Opensuse | 12.3 |
| Opensuse | Opensuse | 13.1 |
| Redhat | Enterprise Linux | 6.0 |
| Redhat | Libvirt | 1.0.0 |
| Redhat | Libvirt | 1.0.1 |
| Redhat | Libvirt | 1.0.2 |
| Redhat | Libvirt | 1.0.3 |
| Redhat | Libvirt | 1.0.4 |
| Redhat | Libvirt | 1.0.5 |
| Redhat | Libvirt | 1.0.5.1 |
| Redhat | Libvirt | 1.0.5.2 |
| Redhat | Libvirt | 1.0.5.3 |
| Redhat | Libvirt | 1.0.5.4 |
| Redhat | Libvirt | 1.0.5.5 |
| Redhat | Libvirt | 1.0.5.6 |
| Redhat | Libvirt | 1.0.6 |
| Redhat | Libvirt | 1.1.0 |
| Redhat | Libvirt | 1.1.1 |
| Redhat | Libvirt | 1.1.2 |
| Redhat | Libvirt | 1.1.3 |
| Redhat | Libvirt | 1.1.4 |
| Redhat | Libvirt | 1.2.0 |
| Redhat | Libvirt | 1.2.1 |
| Redhat | Libvirt | 1.2.2 |
| Redhat | Libvirt | 1.2.3 |
| Redhat | Libvirt | 1.2.4 |
References
- http://security.libvirt.org/2014/0003.htmlPatch, Vendor Advisory
- http://security.libvirt.org/2014/0003.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-5177?
How severe is CVE-2014-5177?
How do I fix CVE-2014-5177?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-5171SAP HANA Extend Application Services (XS) does not encrypt t…
- CVE-2014-5172Multiple cross-site scripting (XSS) vulnerabilities in the X…
- CVE-2014-5173SAP HANA Extend Application Services (XS) allows remote atta…
- CVE-2014-5174The SAP Netweaver Business Warehouse component does not prop…
- CVE-2014-5175The License Measurement servlet in SAP Solution Manager 7.1 …
- CVE-2014-5176SAP FI Manager Self-Service has a hard-coded user name, whic…
- CVE-2014-5178Multiple cross-site scripting (XSS) vulnerabilities in Easy …
- CVE-2014-5179The freelinking module for Drupal, as used in the Freelinkin…
- CVE-2014-5180SQL injection vulnerability in the videos page in the HDW Pl…
- CVE-2014-5181Directory traversal vulnerability in lastfm-proxy.php in the…
- CVE-2014-5182Multiple SQL injection vulnerabilities in the yawpp plugin 1…
- CVE-2014-5183SQL injection vulnerability in includes/mode-edit.php in the…
Are you affected by CVE-2014-5177?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
