Unrated severityNVD Advisory· Published Jan 24, 2014· Updated Apr 29, 2026
CVE-2014-0028
CVE-2014-0028
Description
libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.
Affected products
5Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- bugzilla.redhat.com/show_bug.cginvdVendor Advisory
- libvirt.org/news.htmlnvd
- lists.opensuse.org/opensuse-updates/2014-02/msg00060.htmlnvd
- secunia.com/advisories/60895nvd
- security.gentoo.org/glsa/glsa-201412-04.xmlnvd
- www.ubuntu.com/usn/USN-2093-1nvd
- www.redhat.com/archives/libvir-list/2014-January/msg00684.htmlnvd
News mentions
0No linked articles in our index yet.