3.5
CVSSv2

CVE-2012-3445

Published: 07/08/2012 Updated: 22/03/2013
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 0.9.13

Vendor Advisories

Synopsis Moderate: libvirt security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated libvirt packages that fix one security issue and two bugs are nowavailable for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact ...
Debian Bug report logs - #734556 libvirt: CVE-2013-6458: qemu: job usage issue in several APIs leading to libvirtd crash Package: libvirt; Maintainer for libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 8 Jan 2014 ...
Debian Bug report logs - #683483 CVE-2012-3445 Package: libvirt; Maintainer for libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Wed, 1 Aug 2012 07:51:02 UTC Severity: grave Tags: security Fixed in versions lib ...