Bugzilla – Bug 844052
VUL-0: CVE-2013-4399: libvirt: unprivileged user can crash libvirtd when ACLs are enabled
Last modified: 2014-03-24 08:34:00 UTC
via libvirt security and rh bugzilla CVE-2013-4399 It was discovered that an unprivileged user with read-only access to a libvirt guest could connect to it and, by disconnecting, cause a crash of the guest if the access-driver ACLs were defined in libvirtd.conf. This was due libvirtd not removing event callbacks, which would continue to trigger after the client disconnects, which would cause predictable use of free memory, resulting in a crash. This vulnerability was introduced in libvirt 1.1.0 and fixed in 1.1.3 [1]. [1] http://libvirt.org/git/?p=libvirt.git;a=commit;h=8294aa0c1750dcb49d6345cd9bd97bf421580d8b Acknowledgements: This issue was discovered by Zhenfang Wang of Red Hat. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4399 https://bugzilla.redhat.com/show_bug.cgi?id=1015214
(probably just 13.1+factory, right?)
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (844052) was mentioned in https://build.opensuse.org/request/show/203343 Factory / libvirt
*** Bug 842300 has been marked as a duplicate of this bug. ***
Ok. I fixed the other one :) https://bugzilla.novell.com/show_bug.cgi?id=842300#c3 Thanks!
released