The xenDaemonListDefinedDomains function in xen/xend_internal.c in libvirt 1.1.1 allows remote authenticated users to cause a denial of service (memory corruption and crash) via vectors involving the virConnectListDefinedDomains API function.
References
| Link | Resource |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=996241 | Exploit Patch |
| http://libvirt.org/news.html | |
| http://www.openwall.com/lists/oss-security/2013/08/12/12 | Exploit Patch |
| http://libvirt.org/git/?p=libvirt.git;a=commitdiff;h=0e671a16 | Exploit Patch |
Configurations
Information
Published : 2013-09-30 21:55
Updated : 2013-10-01 15:16
NVD link : CVE-2013-4239
Mitre link : CVE-2013-4239
JSON object : View
Products Affected
redhat
- libvirt
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
