PT-2012-6367 · Opensuse+3 · Libvirt+3

Petr Matousek

+1

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2012-4423

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvirt versions prior to 0.10.2
Description The issue affects the libvirt package in the openSUSE operating system, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Exploitation can occur remotely. The virNetServerProgramDispatchCall function in libvirt is vulnerable to a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with specific conditions.
Recommendations For versions prior to 0.10.2, update to version 0.10.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the virNetServerProgramDispatchCall function to minimize the risk of exploitation.

Fix

Related Identifiers

BDU:2015-05502
BDU:2015-05503
CESA-2012_1359
CVE-2012-4423
OPENSUSE-SU-2013_0274-1
RHSA-2012:1359
RHSA-2012_1359

Affected Products

Centos
Red Hat
Suse
Libvirt