LWN.net Logo

libvirt: remote denial of service

Package(s):libvirt CVE #(s):CVE-2012-3445
Created:August 15, 2012 Updated:September 5, 2012
Description: From the CVE entry:

The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.

Alerts:
openSUSE openSUSE-SU-2012:0991-1 2012-08-15
Red Hat RHSA-2012:1202-01 2012-08-23
Fedora FEDORA-2012-11843 2012-08-22
CentOS CESA-2012:1202 2012-08-24
Oracle ELSA-2012-1202 2012-08-23
Scientific Linux SL-libv-20120823 2012-08-23
Fedora FEDORA-2012-12523 2012-09-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds