CVE-2013-4399

libvirt < 1.1.3 - Denial of Service via Event Handler Use-After-Free

Title source: llm
STIX 2.1

Description

The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60895
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201412-04.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/62972
Patch, Vendor Advisory x_refsource_confirm
http://security.libvirt.org/2013/0013.html

Scores

EPSS 0.0208
EPSS Percentile 79.6%

Details

Status published
Products (50)
redhat/libvirt 0.0.1
redhat/libvirt 0.0.2
redhat/libvirt 0.0.3
redhat/libvirt 0.0.4
redhat/libvirt 0.0.5
redhat/libvirt 0.0.6
redhat/libvirt 0.1.0
redhat/libvirt 0.1.1
redhat/libvirt 0.1.3
redhat/libvirt 0.1.4
... and 40 more
Published Dec 12, 2014
Tracked Since Feb 18, 2026