|
|
| |
|
| |
libvirt: multiple vulnerabilities
| Package(s): | libvirt |
CVE #(s): | CVE-2013-4311
CVE-2013-4296
CVE-2013-5651
|
| Created: | September 19, 2013 |
Updated: | October 2, 2013 |
| Description: |
From the Ubuntu advisory:
It was discovered that libvirt used the pkcheck tool in an unsafe manner. A
local attacker could possibly use this flaw to bypass polkit
authentication. In Ubuntu, libvirt polkit authentication is not enabled by
default. (CVE-2013-4311)
It was discovered that libvirt incorrectly handled certain memory stats
requests. A remote attacker could use this issue to cause libvirt to
crash, resulting in a denial of service. This issue only affected Ubuntu
12.04 LTS, Ubuntu 12.10, and Ubuntu 13.04. (CVE-2013-4296)
It was discovered that libvirt incorrectly handled certain bitmap
operations. A remote attacker could use this issue to cause libvirt to
crash, resulting in a denial of service. This issue only affected Ubuntu
13.04. (CVE-2013-5651) |
| Alerts: |
|
( Log in to post comments)
|
|
|