CVE-2013-2230: Input Validation
A flaw was found in the way multiple events registration were handled in libvirt qemu driver.
A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd.
Acknowledgements:
This issue was discovered by Zhenfeng Wang of Red Hat.
Other sources
The qemu driver (qemu/qemudriver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via unspecified vectors involving "multiple events registration."
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2230?
CVE-2013-2230 has been classified as a moderate severity vulnerability.
How do I fix CVE-2013-2230?
To fix CVE-2013-2230, update to a fixed version of libvirt that addresses this flaw.
What are the potential impacts of CVE-2013-2230?
CVE-2013-2230 may allow remote users to crash the libvirt daemon by exploiting the vulnerability.
Which versions of libvirt are affected by CVE-2013-2230?
CVE-2013-2230 affects multiple versions of libvirt prior to version 1.1.0.
Who discovered CVE-2013-2230?
CVE-2013-2230 was discovered by Zhenfeng Wang of Red Hat.