---
title: "CVE-2014-0179\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-0179?format=md
keywords: index, follow
---

# CVE-2014-0179

Publication date 3 August 2014

Last updated 4 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a
denial of service (read block and hang) via a crafted XML document
containing an XML external entity declaration in conjunction with an entity
reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API
method, related to an XML External Entity (XXE) issue. NOTE: this issue
was SPLIT per ADT3 due to different affected versions of some vectors.
CVE-2014-5177 is used for other API methods.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-0179?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libvirt | 14.04 LTS trusty | Fixed 1.2.2-0ubuntu13.1.5 |
| 13.10 saucy | Ignored end of life |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Fixed 0.9.8-2ubuntu17.20 |
| 10.04 LTS lucid | Fixed 0.7.5-5ubuntu27.25 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2014-0179?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

non-default configuration

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| libvirt | * Upstream:   <http://libvirt.org/git/?p=libvirt.git;a=commit;h=d6b27d3e4c40946efa79e91d134616b41b1666c4> * Upstream:   <http://libvirt.org/git/?p=libvirt.git;a=commit;h=be7a5de9d0c406f36efae3230e1743c613ad6945> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0179)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-0179)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-0179)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-0179)

### Related Ubuntu Security Notices (USN)

+ [USN-2366-1](https://usn.ubuntu.com/USN-2366-1)
+ libvirt vulnerabilities
+ 30 September 2014

### Other references

* <https://www.redhat.com/archives/libvir-list/2014-May/msg00209.html>
* <http://security.libvirt.org/2014/0003.html>
* <https://www.cve.org/CVERecord?id=CVE-2014-0179>
