5.2
CVSSv2

CVE-2013-6457

Published: 24/01/2014 Updated: 03/01/2015
CVSS v2 Base Score: 5.2 | Impact Score: 6.4 | Exploitability Score: 5.1
VMScore: 463
Vector: AV:A/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt prior to 1.2.1 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 0.0.5

redhat libvirt 0.0.6

redhat libvirt 0.1.0

redhat libvirt 0.1.1

redhat libvirt 0.10.2.4

redhat libvirt 0.10.2.5

redhat libvirt 0.10.2.6

redhat libvirt 0.10.2.7

redhat libvirt 0.4.3

redhat libvirt 0.4.4

redhat libvirt 0.4.5

redhat libvirt 0.4.6

redhat libvirt 0.7.5

redhat libvirt 0.7.6

redhat libvirt 0.7.7

redhat libvirt 0.8.0

redhat libvirt 0.9.11.2

redhat libvirt 0.9.11.3

redhat libvirt 0.9.11.4

redhat libvirt 0.9.11.5

redhat libvirt 0.9.6.3

redhat libvirt 0.9.7

redhat libvirt 0.9.8

redhat libvirt 0.9.9

redhat libvirt 1.0.0

redhat libvirt 1.1.0

redhat libvirt 1.1.1

redhat libvirt 1.1.2

redhat libvirt 1.1.3

redhat libvirt 0.0.1

redhat libvirt 0.0.3

redhat libvirt 0.1.4

redhat libvirt 0.1.6

redhat libvirt 0.10.1

redhat libvirt 0.10.2.1

redhat libvirt 0.10.2.3

redhat libvirt 0.10.2.8

redhat libvirt 0.2.1

redhat libvirt 0.4.0

redhat libvirt 0.4.2

redhat libvirt 0.5.0

redhat libvirt 0.6.0

redhat libvirt 0.6.2

redhat libvirt 0.7.1

redhat libvirt 0.7.3

redhat libvirt 0.8.2

redhat libvirt 0.8.4

redhat libvirt 0.9.0

redhat libvirt 0.9.10

redhat libvirt 0.9.11.1

redhat libvirt 0.9.11.6

redhat libvirt 0.9.11.8

redhat libvirt 0.9.6

redhat libvirt 0.9.6.2

redhat libvirt 1.0.2

redhat libvirt 1.0.4

redhat libvirt 1.0.5.4

redhat libvirt 1.0.5.6

redhat libvirt

redhat libvirt 0.1.7

redhat libvirt 0.1.8

redhat libvirt 0.1.9

redhat libvirt 0.10.0

redhat libvirt 0.2.3

redhat libvirt 0.3.0

redhat libvirt 0.3.1

redhat libvirt 0.3.2

redhat libvirt 0.6.3

redhat libvirt 0.6.4

redhat libvirt 0.6.5

redhat libvirt 0.7.0

redhat libvirt 0.8.5

redhat libvirt 0.8.6

redhat libvirt 0.8.7

redhat libvirt 0.8.8

redhat libvirt 0.9.13

redhat libvirt 0.9.2

redhat libvirt 0.9.3

redhat libvirt 0.9.4

redhat libvirt 1.0.5

redhat libvirt 1.0.5.1

redhat libvirt 1.0.5.2

redhat libvirt 1.0.5.3

redhat libvirt 0.0.2

redhat libvirt 0.0.4

redhat libvirt 0.1.3

redhat libvirt 0.1.5

redhat libvirt 0.10.2

redhat libvirt 0.10.2.2

redhat libvirt 0.2.0

redhat libvirt 0.2.2

redhat libvirt 0.3.3

redhat libvirt 0.4.1

redhat libvirt 0.5.1

redhat libvirt 0.6.1

redhat libvirt 0.7.2

redhat libvirt 0.7.4

redhat libvirt 0.8.1

redhat libvirt 0.8.3

redhat libvirt 0.9.1

redhat libvirt 0.9.11

redhat libvirt 0.9.11.7

redhat libvirt 0.9.12

redhat libvirt 0.9.5

redhat libvirt 0.9.6.1

redhat libvirt 1.0.1

redhat libvirt 1.0.3

redhat libvirt 1.0.5.5

redhat libvirt 1.0.6

redhat libvirt 1.1.4

Vendor Advisories

Debian Bug report logs - #735676 libvirt: CVE-2014-0028 Package: libvirt; Maintainer for libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Fri, 17 Jan 2014 11:54:01 UTC Severity: important Tags: security Fixed in version li ...
Several security issues were fixed in libvirt ...
The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driverc) in libvirt before 121 does not properly initialize the nodemap, which allows local users to cause a denial of service (invalid free operation and crash) or possibly execute arbitrary code via an inactive domain to the virsh numatune command ...