PT-2011-1125 · Red Hat · Libvirt-Devel+5

Petr Matousek

·

Published

2011-05-02

·

Updated

2023-02-13

·

CVE-2011-1486

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvirt versions prior to 0.9.0 libvirt-debuginfo versions 0.8.1 libvirt-devel versions 0.8.1 libvirt-python versions 0.8.1 libvirt-client versions 0.8.1
Description The issue affects the libvirt package in Red Hat Enterprise Linux, potentially leading to a breach of confidentiality, integrity, and availability of protected information. Exploitation can be performed locally. The problem with libvirtd in libvirt before version 0.9.0 is that it does not use thread-safe error reporting, allowing remote attackers to cause a denial of service by reporting errors simultaneously.
Recommendations For libvirt versions prior to 0.9.0, update to version 0.9.0 or later to resolve the issue. For libvirt-debuginfo, libvirt-devel, libvirt-python, and libvirt-client versions 0.8.1, consider disabling local access until a patch is available. As a temporary workaround, restrict local exploitation to minimize the risk of breach.

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2015-06818
BDU:2015-06820
BDU:2015-06821
BDU:2015-06822
BDU:2015-06825
CVE-2011-1486
DSA-2280-1
RHSA-2011:0478
RHSA-2011:0479
RHSA-2011_0478
RHSA-2011_0479

Affected Products

Red Hat
Libvirt
Libvirt-Client
Libvirt-Debuginfo
Libvirt-Devel
Libvirt-Python