CVE Vulnerabilities

CVE-2012-3445

Published: Aug 07, 2012 | Modified: Mar 22, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V2
3.3 MODERATE
AV:A/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.

Affected Software

Name Vendor Start Version End Version
Libvirt Redhat 0.9.13 (including) 0.9.13 (including)
Red Hat Enterprise Linux 6 RedHat libvirt-0:0.9.10-21.el6_3.4 *
Libvirt Ubuntu devel *
Libvirt Ubuntu hardy *

References