oss-sec mailing list archives

[NOT A CVE REQUEST] CVE-2013-2230 -- libvirt: multiple registered events crash


From: Petr Matousek <pmatouse () redhat com>
Date: Wed, 10 Jul 2013 14:28:49 +0200

A flaw was found in the way multiple events registration were handled in
libvirt qemu driver.

A remote user able to issue commands to libvirt daemon could use this
flaw to crash libvirtd.

Upstream fix:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=f38c8185f97720ecae7ef2291fbaa5d6b0209e17

References:
https://bugzilla.redhat.com/show_bug.cgi?id=981476

Thanks,
-- 
Petr Matousek / Red Hat Security Response Team


Current thread: