CVE Vulnerabilities

CVE-2013-4154

Published: Sep 30, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to agent based cpu (un)plug, as demonstrated by the virsh vcpucount foobar –guest command.

Affected Software

Name Vendor Start Version End Version
Libvirt Redhat * 1.1.0 (including)
Libvirt Redhat 1.0.0 (including) 1.0.0 (including)
Libvirt Redhat 1.0.1 (including) 1.0.1 (including)
Libvirt Redhat 1.0.2 (including) 1.0.2 (including)
Libvirt Redhat 1.0.3 (including) 1.0.3 (including)
Libvirt Redhat 1.0.4 (including) 1.0.4 (including)
Libvirt Redhat 1.0.5 (including) 1.0.5 (including)
Libvirt Redhat 1.0.6 (including) 1.0.6 (including)

References