4.4
CVSSv2

CVE-2009-0036

Published: 11/02/2009 Updated: 13/02/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 445
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privileges by sending a portion of the header of a virProxyPacket packet, and then sending the remainder of the packet with crafted values in the header, related to use of uninitialized memory in a validation check.

Vulnerable Product Search on Vulmon Subscribe to Product

libvirt libvirt 0.5.1

Vendor Advisories

Synopsis Moderate: libvirt security update Type/Severity Security Advisory: Moderate Topic Updated libvirt packages that fix two security issues are now available forRed Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team[Updated 5th May ...

Exploits

/* * cve-2009-0036c * * libvirt_proxy <= 051 Local Privilege Escalation Exploit * Jon Oberheide <jon@oberheideorg> * jonoberheideorg * * Information: * * cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2009-0036 * * Buffer overflow in the proxyReadClientSocket function in * proxy/libvirt_proxyc in libvirt ...
libvirt_proxy versions 051 and below local privilege escalation exploit ...