Security Advisory

CVE-2014-0028

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-01-24 18:00:00
Last updated 2024-08-06 08:58:26
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.