Back

LOW

libvirt: crash in virTypedParameterArrayClear

Published Aug 7, 2012

Description

The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.

Affected products

Remediation

Red Hat statement

The versions of libvirt as shipped with Red Hat Enterprise Linux 5 are not affected. Future libvirt updates for Red Hat Enterprise Linux 6 may address this flaw.

Metrics

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 7, 2012
Updated Aug 6, 2024
Reserved Jun 14, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jul 30, 2012