4.3
CVSSv2

CVE-2013-4154

Published: 30/09/2013 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The qemuAgentCommand function in libvirt prior to 1.1.1, when a guest agent is not configured, allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 1.0.5

redhat libvirt 1.0.4

redhat libvirt 1.0.1

redhat libvirt

redhat libvirt 1.0.6

redhat libvirt 1.0.2

redhat libvirt 1.0.3

redhat libvirt 1.0.0

Vendor Advisories

Debian Bug report logs - #717355 libvirt: CVE-2013-4154: crash of libvirtd without guest agent configuration Package: libvirt; Maintainer for libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Henri Salo <henri@nervfi> Date: Fri, 19 Jul 2013 17:51:06 UTC Severity: i ...
Debian Bug report logs - #717354 libvirt: CVE-2013-4153: double free of returned JSON array in qemuAgentGetVCPUs() Package: libvirt; Maintainer for libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Henri Salo <henri@nervfi> Date: Fri, 19 Jul 2013 17:51:01 UTC Sever ...
The qemuAgentCommand function in libvirt before 111, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command ...