qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] oss-security - CVE-2014-3672 libvirt: DoS via excessive logging
@ 2016-07-21  2:24 Xulei (Stone)
  2016-07-21  8:55 ` Daniel P. Berrange
  0 siblings, 1 reply; 2+ messages in thread
From: Xulei (Stone) @ 2016-07-21  2:24 UTC (permalink / raw)
  To: Ian.Jackson, berrange; +Cc: qemu-devel

Hi,

A CVE(CVE-2014-3672) vulnerability was reported in Xen. 
I want to know how to reproduce this CVE and whether the qemu-kvm was affected ?

Hyperlink: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3672
Hyperlink: http://www.openwall.com/lists/oss-security/2016/05/24/5

Thank you.

--------------
Xulei (Stone)

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [Qemu-devel] oss-security - CVE-2014-3672 libvirt: DoS via excessive logging
  2016-07-21  2:24 [Qemu-devel] oss-security - CVE-2014-3672 libvirt: DoS via excessive logging Xulei (Stone)
@ 2016-07-21  8:55 ` Daniel P. Berrange
  0 siblings, 0 replies; 2+ messages in thread
From: Daniel P. Berrange @ 2016-07-21  8:55 UTC (permalink / raw)
  To: Xulei (Stone); +Cc: Ian.Jackson, qemu-devel

On Thu, Jul 21, 2016 at 02:24:43AM +0000, Xulei (Stone) wrote:
> Hi,
> 
> A CVE(CVE-2014-3672) vulnerability was reported in Xen. 
> I want to know how to reproduce this CVE and whether the qemu-kvm was affected ?
> 
> Hyperlink: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3672
> Hyperlink: http://www.openwall.com/lists/oss-security/2016/05/24/5

Yes, QEMU is affected, but we did not fix it at the QEMU layer. Instead
libvirt has introduced a virtlogd daemon to handle all writing of data
to files. So QEMU now merely writes a pipe FD, and virtlogd takes care
of file rotation.

Regards,
Daniel
-- 
|: http://berrange.com      -o-    http://www.flickr.com/photos/dberrange/ :|
|: http://libvirt.org              -o-             http://virt-manager.org :|
|: http://autobuild.org       -o-         http://search.cpan.org/~danberr/ :|
|: http://entangle-photo.org       -o-       http://live.gnome.org/gtk-vnc :|

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2016-07-21  8:55 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-07-21  2:24 [Qemu-devel] oss-security - CVE-2014-3672 libvirt: DoS via excessive logging Xulei (Stone)
2016-07-21  8:55 ` Daniel P. Berrange

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).