oss-sec mailing list archives
Re: CVE request -- libvirt: virBitmapParse out-of-bounds read access
From: cve-assign () mitre org
Date: Fri, 30 Aug 2013 02:44:35 -0400 (EDT)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
The virBitmapParse function was calling virBitmapIsSet() function that requires the caller to check the bounds of the bitmap without checking them. This resulted into crashes when parsing a bitmap string that was exceeding the bounds used as argument. https://bugzilla.redhat.com/show_bug.cgi?id=997367 Upstream fix: http://libvirt.org/git/?p=libvirt.git;a=commit;h=47b9127e883677a0d60d767030a147450e919a25
Use CVE-2013-5651. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJSIDcdAAoJEGvefgSNfHMdgoYH/1X2pJ8TbloT/iT9TpqTg2p1 LplZwtLXbAqIwB1Rx79T1HxRvA72JkefgLlhPHMGmssKCAwfeZ3x0nGS4BnOnq9e i/dUa+InOznXMxEEsudl8AvGxepTpCk44j+Y4ab0XGllotzDM5iMWCjQItnVQxRi Yrms8W92Pn0WxTyMhfV5E8tQiEJwxTi3wih3vWE8RxPNuVDqS7qjnJk0Fzs/0RlY R4TRtaqsI4n3zY0pCtYYSwmoVGXOR0GA9MFJ39YzxtoKiw8nS/Xshf6/lffmxYlN 1vH1ONyOEGmOamYQhnlJleHydAEfDGmptchEsHQTrpb7yvYsgsWw69wZ9yoCxzw= =uCdo -----END PGP SIGNATURE-----
Current thread:
- CVE request -- libvirt: virBitmapParse out-of-bounds read access Petr Matousek (Aug 29)
- Re: CVE request -- libvirt: virBitmapParse out-of-bounds read access cve-assign (Aug 29)