DSA-2764-1 libvirt -- programming error

Related Vulnerabilities: CVE-2013-4296  

Daniel P. Berrange discovered that incorrect memory handling in the remoteDispatchDomainMemoryStats() function could lead to denial of service. The oldstable distribution (squeeze) is not affected. For the stable distribution (wheezy), this problem has been fixed in version 0.9.12-11+deb7u4. This update also includes some non-security related bugfixes scheduled for the upcoming Wheezy 7.2 point release. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your libvirt packages.

Debian Security Advisory

DSA-2764-1 libvirt -- programming error

Date Reported:
25 Sep 2013
Affected Packages:
libvirt
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2013-4296.
More information:

Daniel P. Berrange discovered that incorrect memory handling in the remoteDispatchDomainMemoryStats() function could lead to denial of service.

The oldstable distribution (squeeze) is not affected.

For the stable distribution (wheezy), this problem has been fixed in version 0.9.12-11+deb7u4. This update also includes some non-security related bugfixes scheduled for the upcoming Wheezy 7.2 point release.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your libvirt packages.