4.3
CVSSv2

CVE-2013-2124

Published: 27/05/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x prior to 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote malicious users to cause a denial of service (crash) via empty guest files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libguestfs libguestfs 1.21.39

libguestfs libguestfs 1.21.38

libguestfs libguestfs 1.21.37

libguestfs libguestfs 1.21.30

libguestfs libguestfs 1.21.29

libguestfs libguestfs 1.21.22

libguestfs libguestfs 1.21.21

libguestfs libguestfs 1.21.13

libguestfs libguestfs 1.21.12

libguestfs libguestfs 1.21.5

libguestfs libguestfs 1.21.4

libguestfs libguestfs 1.20.1

libguestfs libguestfs 1.20.2

libguestfs libguestfs 1.21.34

libguestfs libguestfs 1.21.33

libguestfs libguestfs 1.21.26

libguestfs libguestfs 1.21.25

libguestfs libguestfs 1.21.18

libguestfs libguestfs 1.21.17

libguestfs libguestfs 1.21.9

libguestfs libguestfs 1.21.8

libguestfs libguestfs 1.21.1

libguestfs libguestfs 1.22.0

libguestfs libguestfs 1.20.5

libguestfs libguestfs 1.20.6

libguestfs libguestfs 1.21.36

libguestfs libguestfs 1.21.35

libguestfs libguestfs 1.21.28

libguestfs libguestfs 1.21.27

libguestfs libguestfs 1.21.20

libguestfs libguestfs 1.21.19

libguestfs libguestfs 1.21.11

libguestfs libguestfs 1.21.10

libguestfs libguestfs 1.21.3

libguestfs libguestfs 1.21.2

libguestfs libguestfs 1.20.3

libguestfs libguestfs 1.20.4

libguestfs libguestfs 1.21.40

libguestfs libguestfs 1.21.32

libguestfs libguestfs 1.21.31

libguestfs libguestfs 1.21.24

libguestfs libguestfs 1.21.23

libguestfs libguestfs 1.21.16

libguestfs libguestfs 1.21.15

libguestfs libguestfs 1.21.14

libguestfs libguestfs 1.21.7

libguestfs libguestfs 1.21.6

libguestfs libguestfs 1.23.0

libguestfs libguestfs 1.20.0

Vendor Advisories

Debian Bug report logs - #710290 libguestfs: CVE-2013-2124: Denial of service due to a double-free when inspecting certain guest files / images Package: libguestfs; Maintainer for libguestfs is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Henri Salo <henri@nervfi> Date: W ...
Double free vulnerability in inspect-fsc in LibguestFS 120x before 1207, 121x, 1220, and 1230 allows remote attackers to cause a denial of service (crash) via empty guest files ...