Vulnerability Description
The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a crafted RPC call.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Libvirt | 0.9.1 |
| Canonical | Ubuntu Linux | 10.04 |
| Redhat | Enterprise Linux | 6.0 |
Related Weaknesses (CWE)
References
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=e7f400a110e2e3673b96518170b
- http://lists.opensuse.org/opensuse-updates/2013-10/msg00023.html
- http://lists.opensuse.org/opensuse-updates/2013-10/msg00024.html
- http://rhn.redhat.com/errata/RHSA-2013-1272.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1460.html
- http://secunia.com/advisories/60895
- http://security.gentoo.org/glsa/glsa-201412-04.xml
- http://wiki.libvirt.org/page/Maintenance_ReleasesPatch
- http://www.debian.org/security/2013/dsa-2764
- http://www.ubuntu.com/usn/USN-1954-1Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1006173Patch
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=e7f400a110e2e3673b96518170b
- http://lists.opensuse.org/opensuse-updates/2013-10/msg00023.html
- http://lists.opensuse.org/opensuse-updates/2013-10/msg00024.html
- http://rhn.redhat.com/errata/RHSA-2013-1272.htmlVendor Advisory
FAQ
What is CVE-2013-4296?
CVE-2013-4296 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated us...
How severe is CVE-2013-4296?
CVE-2013-4296 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4296?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Libvirt, Canonical Ubuntu Linux, Redhat Enterprise Linux.