PT-2012-6367 · Opensuse+3 · Libvirt+3
Petr Matousek
+1
·
Published
1970-01-01
·
Updated
2023-02-13
·
CVE-2012-4423
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libvirt versions prior to 0.10.2
Description
The issue affects the libvirt package in the openSUSE operating system, potentially leading to breaches of confidentiality, integrity, and availability of protected information. Exploitation can occur remotely. The
virNetServerProgramDispatchCall function in libvirt is vulnerable to a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with specific conditions.Recommendations
For versions prior to 0.10.2, update to version 0.10.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the
virNetServerProgramDispatchCall function to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Red Hat
Suse
Libvirt