Back

MEDIUM

libvirt: null function pointer invocation in virNetServerProgramDispatchCall()

Published Nov 19, 2012

Description

The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.

Affected products

Remediation

Red Hat statement

The versions of libvirt as shipped with Red Hat Enterprise Linux 5 are not affected. This issue did affect the versions of the libvirt package as shipped with Red Hat Enterprise Linux 6.

Metrics

Weaknesses (0)

No CWE recorded.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 19, 2012
Updated Aug 6, 2024
Reserved Aug 21, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jul 24, 2012