First published: Tue Sep 10 2013(Updated: )
The 'stats' variable in remoteDispatchDomainMemoryStats function was not initialized to NULL, so if some early validation of the RPC call fails, it is possible to jump to the 'cleanup' label and VIR_FREE an uninitialized pointer. A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd. Acknowledgements: This issue was discovered by Daniel P. Berrange of Red Hat.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Libvirt | =0.9.1 | |
Redhat Libvirt | =0.9.2 | |
Redhat Libvirt | =0.9.3 | |
Redhat Libvirt | =0.9.4 | |
Redhat Libvirt | =0.9.5 | |
Redhat Libvirt | =0.9.6 | |
Redhat Libvirt | =0.9.7 | |
Redhat Libvirt | =0.9.8 | |
Redhat Libvirt | =0.9.9 | |
Redhat Libvirt | =0.9.10 | |
Redhat Libvirt | =0.9.11 | |
Redhat Libvirt | =0.9.12 | |
Redhat Libvirt | =0.9.13 | |
Redhat Libvirt | =0.10.0 | |
Redhat Libvirt | =0.10.1 | |
Redhat Libvirt | =0.10.2 | |
Redhat Libvirt | =0.10.2.1 | |
Redhat Libvirt | =0.10.2.2 | |
Redhat Libvirt | =0.10.2.3 | |
Redhat Libvirt | =0.10.2.4 | |
Redhat Libvirt | =0.10.2.5 | |
Redhat Libvirt | =0.10.2.6 | |
Redhat Libvirt | =0.10.2.7 | |
Redhat Libvirt | =1.0.5.1 | |
Redhat Libvirt | =1.0.5.2 | |
Redhat Libvirt | =1.0.5.3 | |
Redhat Libvirt | =1.0.5.4 | |
Redhat Libvirt | =1.0.5.5 | |
Redhat Libvirt | =1.1.0 | |
Redhat Libvirt | =1.1.1 | |
Canonical Ubuntu Linux | =10.04 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =12.10 | |
Canonical Ubuntu Linux | =13.04 | |
Red Hat Enterprise Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.