1.9
CVSSv2

CVE-2013-7336

Published: 07/05/2014 Updated: 07/11/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt prior to 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus function.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 1.0.5.4

redhat libvirt 1.0.5.3

redhat libvirt 1.0.5

redhat libvirt 1.0.5.6

redhat libvirt 1.0.4

redhat libvirt 1.0.1

redhat libvirt 1.0.6

redhat libvirt 1.0.2

redhat libvirt 1.1.1

redhat libvirt 1.0.5.1

redhat libvirt 1.0.5.2

redhat libvirt 1.0.3

redhat libvirt 1.0.5.5

redhat libvirt

redhat libvirt 1.0.0

redhat libvirt 1.1.0

opensuse opensuse 13.1

Vendor Advisories

Several security issues were fixed in libvirt ...
The qemuMigrationWaitForSpice function in qemu/qemu_migrationc in libvirt before 113 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigratio ...