Bug 868943 (CVE-2013-7336) - VUL-0: CVE-2013-7336: libvirt: unprivileged user can crash libvirtd during spice migration
Summary: VUL-0: CVE-2013-7336: libvirt: unprivileged user can crash libvirtd during sp...
Status: RESOLVED DUPLICATE of bug 842301
Alias: CVE-2013-7336
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 12.3
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/97104/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-03-18 15:29 UTC by Marcus Meissner
Modified: 2015-02-19 01:48 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2014-03-18 15:29:26 UTC
via oss-sec / rh bugzilla

Domblkstat is possible even with read-only connection, so whenever
migration with spice is done and domblkstat gets called at the same time
as qemuMonitorGetSpiceMigrationStatus(), there is certain possibility that
the daemon crashes.

An unprivileged user able to issue commands to running libvirtd could use
this flaw to crash libvirtd and prevent more privileged clients from
working correctly.

Upstream fix:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=484cc321

Acknowledgements:

This issue was discovered by Marian Krcmarik of Red Hat.


References:
https://bugzilla.redhat.com/show_bug.cgi?id=1077620
Comment 1 James Fehlig 2014-03-18 17:51:33 UTC
The fix has been in libvirt since release 1.1.3, so it looks like this affects openSUSE12.3 and 13.1.  We don't support SPICE in SLE11, so nothing to be done there.
Comment 2 Swamp Workflow Management 2014-03-18 23:00:17 UTC
bugbot adjusting priority
Comment 3 James Fehlig 2014-03-19 20:41:48 UTC
Opps, I got it wrong about when this issue was introduced.  It was introduced in v1.1.0 by commit 9da7b11b and fixed in v1.1.3 by commit 484cc321, so only openSUSE13.1 is affected.
Comment 4 James Fehlig 2014-03-21 18:55:17 UTC
Heh, this bug is actually a duplicate of bnc#842301, which was fixed some time ago.

Nonetheless, I changed the name of the patch to include the CVE number and have submitted a maintenance request for openSUSE13.1 to fix bnc#852005 and bnc#857490, the latter being CVE-2013-6456.  MR#227061.

I'll defer closing this as duplicate to the security team.
Comment 5 Marcus Meissner 2014-03-27 08:05:47 UTC
close

*** This bug has been marked as a duplicate of bug 842301 ***
Comment 6 Swamp Workflow Management 2014-05-02 13:04:56 UTC
openSUSE-SU-2014:0593-1: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 852005,857490,868943,871154,873103
CVE References: CVE-2013-6456,CVE-2013-7336
Sources used:
openSUSE 13.1 (src):    libvirt-1.1.2-2.26.1