Bug 844052 (CVE-2013-4399) - VUL-0: CVE-2013-4399: libvirt: unprivileged user can crash libvirtd when ACLs are enabled
Summary: VUL-0: CVE-2013-4399: libvirt: unprivileged user can crash libvirtd when ACLs...
Status: RESOLVED FIXED
: 842300 (view as bug list)
Alias: CVE-2013-4399
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-10-04 10:57 UTC by Marcus Meissner
Modified: 2014-03-24 08:34 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-10-04 10:57:38 UTC
via libvirt security and rh bugzilla

CVE-2013-4399

It was discovered that an unprivileged user with read-only access to a libvirt guest could connect to it and, by disconnecting, cause a crash of the guest if the access-driver ACLs were defined in libvirtd.conf.  This was due libvirtd not removing event callbacks, which would continue to trigger after the client disconnects, which would cause predictable use of free memory, resulting in a crash.

This vulnerability was introduced in libvirt 1.1.0 and fixed in 1.1.3 [1].

[1] http://libvirt.org/git/?p=libvirt.git;a=commit;h=8294aa0c1750dcb49d6345cd9bd97bf421580d8b


Acknowledgements:

This issue was discovered by Zhenfang Wang of Red Hat.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4399
https://bugzilla.redhat.com/show_bug.cgi?id=1015214
Comment 1 Marcus Meissner 2013-10-04 10:58:05 UTC
(probably just 13.1+factory, right?)
Comment 2 Swamp Workflow Management 2013-10-04 22:00:12 UTC
bugbot adjusting priority
Comment 4 Bernhard Wiedemann 2013-10-15 06:01:42 UTC
This is an autogenerated message for OBS integration:
This bug (844052) was mentioned in
https://build.opensuse.org/request/show/203343 Factory / libvirt
Comment 5 Marcus Meissner 2013-10-15 07:58:05 UTC
*** Bug 842300 has been marked as a duplicate of this bug. ***
Comment 7 James Fehlig 2013-10-17 17:37:05 UTC
Ok.  I fixed the other one :)

https://bugzilla.novell.com/show_bug.cgi?id=842300#c3

Thanks!
Comment 8 Marcus Meissner 2014-03-24 08:34:00 UTC
released