|
|
| |
|
| |
libvirt: remote denial of service
| Package(s): | libvirt |
CVE #(s): | CVE-2012-3445
|
| Created: | August 15, 2012 |
Updated: | September 5, 2012 |
| Description: |
From the CVE entry:
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer. |
| Alerts: |
|
( Log in to post comments)
|
|
|