The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libvirt | Redhat | 0.9.13 (including) | 0.9.13 (including) |
Red Hat Enterprise Linux 6 | RedHat | libvirt-0:0.9.10-21.el6_3.4 | * |
Libvirt | Ubuntu | devel | * |
Libvirt | Ubuntu | hardy | * |