LWN.net Logo

libvirt: denial of service

Package(s):libvirt CVE #(s):CVE-2011-2511
Created:July 12, 2011 Updated:September 23, 2011
Description: From the Red Hat bugzilla:

It has been found that calling VirDomainGetVcpus with bogus parameters can lead to integer overflow and subsequent heap corruption. A remote attacker could use this flaw to crash libvirtd (DoS).

Alerts:
CentOS CESA-2011:1019 2011-09-22
Scientific Linux SL-libv-20110823 2011-08-23
Scientific Linux SL-libv-20110721 2011-07-21
Red Hat RHSA-2011:1197-01 2011-08-23
openSUSE openSUSE-SU-2011:0900-1 2011-08-15
Ubuntu USN-1180-1 2011-07-28
Fedora FEDORA-2011-9062 2011-07-06
Red Hat RHSA-2011:1019-01 2011-07-21
Debian DSA-2280-1 2011-07-19
Fedora FEDORA-2011-9091 2011-07-06
Gentoo 201202-07 2012-02-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds