Bug 830498 (CVE-2013-4154) - VUL-0: libvirt: CVE-2013-4154: crash of libvirtd without guest agent configuration
Summary: VUL-0: libvirt: CVE-2013-4154: crash of libvirtd without guest agent configur...
Status: RESOLVED FIXED
Alias: CVE-2013-4154
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-07-22 06:40 UTC by Sebastian Krahmer
Modified: 2013-07-25 09:18 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2013-07-22 06:40:27 UTC
Public via OSS-sec:

Date: Fri, 19 Jul 2013 18:14:52 +0200
From: Petr Matousek
To: oss-security
Cc: libvirt-security


If users haven't configured guest agent then qemuAgentCommand() will
dereference a NULL 'mon' pointer.

A remote user able to issue commands to libvirt daemon could use this
flaw to crash libvirtd.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=986386
https://bugzilla.redhat.com/show_bug.cgi?id=984821
https://www.redhat.com/archives/libvir-list/2013-July/msg00992.html

Upstream fix:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=96518d4316b711c72205117f8d5c967d5127bbb6

Thanks,
--
Petr Matousek / Red Hat Security Response Team
~
Comment 1 James Fehlig 2013-07-22 17:07:05 UTC
This CVE (and CVE-2013-4153) only affects libvirt 1.1.0, which only affects Factory.  I've added patches for both CVE's and submitted a new libvirt 1.1.0 package to Factory - SR#184015.

I think this can be closed now, but will leave that to the security team.
Comment 2 Bernhard Wiedemann 2013-07-22 18:00:07 UTC
This is an autogenerated message for OBS integration:
This bug (830498) was mentioned in
https://build.opensuse.org/request/show/184015 Factory / libvirt
Comment 3 Swamp Workflow Management 2013-07-22 22:00:36 UTC
bugbot adjusting priority
Comment 4 Sebastian Krahmer 2013-07-23 06:16:16 UTC
closing