CVE-2012-3445
published 2012-08-07CVE-2012-3445: The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote…
PriorityP415low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
2.16%
80.2th percentile
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 0.9.12-4 (bookworm) | libvirt 0.9.12-4 (bookworm) |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 0.9.12-4 | 0.9.12-4 |
| redhat | libvirt | >= 0 < 0.9.12-4 | 0.9.12-4 |
| redhat | libvirt | >= 0 < 0.9.12-4 | 0.9.12-4 |
| redhat | libvirt | >= 0 < 0.9.12-4 | 0.9.12-4 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-65xv-xg43-h8gj: The virTypedParameterArrayClear function in libvirt 0
ghsa_unreviewed·2022-05-17
CVE-2012-3445 [LOW] GHSA-65xv-xg43-h8gj: The virTypedParameterArrayClear function in libvirt 0
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
OSV
CVE-2012-3445: The virTypedParameterArrayClear function in libvirt 0
osv·2012-08-07·CVSS 3.5
CVE-2012-3445 [LOW] CVE-2012-3445: The virTypedParameterArrayClear function in libvirt 0
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
Red Hat
libvirt: crash in virTypedParameterArrayClear
vendor_redhat·2012-07-30·CVSS 3.5
CVE-2012-3445 [LOW] libvirt: crash in virTypedParameterArrayClear
libvirt: crash in virTypedParameterArrayClear
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
Statement: The versions of libvirt as shipped with Red Hat Enterprise Linux 5 are not affected.
Future libvirt updates for Red Hat Enterprise Linux 6 may address this flaw.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-3445: libvirt - The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly han...
vendor_debian·2012·CVSS 3.5
CVE-2012-3445 [LOW] CVE-2012-3445: libvirt - The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly han...
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
Scope: local
bookworm: resolved (fixed in 0.9.12-4)
bullseye: resolved (fixed in 0.9.12-4)
forky: resolved (fixed in 0.9.12-4)
sid: resolved (fixed in 0.9.12-4)
trixie: resolved (fixed in 0.9.12-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3445 libvirt: crash in virTypedParameterArrayClear
bugzilla·2012-07-31·CVSS 3.5
CVE-2012-3445 [LOW] CVE-2012-3445 libvirt: crash in virTypedParameterArrayClear
CVE-2012-3445 libvirt: crash in virTypedParameterArrayClear
It has been found that sending crafted RPC command with nparams set to 0 can lead to libvirtd accessing random memory, possibly leading to crash. A remote attacker could use this flaw to crash libvirtd (DoS).
Upstream proposed fix:
https://www.redhat.com/archives/libvir-list/2012-July/msg01650.html
Discussion:
Statement:
The versions of libvirt as shipped with Red Hat Enterprise Linux 5 are not affected.
Future libvirt updates for Red Hat Enterprise Linux 6 may address this flaw.
---
Created libvirt tracking bugs for this issue
Affects: fedora-all [bug 844745]
---
libvirt-0.9.6.2-1.fc16 has been pushed to the Fedora 16 stable repository. If problems still persist, please make note of it in this bug report.
---
This is
Bugzilla
CVE-2012-3445 libvirt: crash in virTypedParameterArrayClear [fedora-all]
bugzilla·2012-07-31·CVSS 3.5
CVE-2012-3445 [LOW] CVE-2012-3445 libvirt: crash in virTypedParameterArrayClear [fedora-all]
CVE-2012-3445 libvirt: crash in virTypedParameterArrayClear [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bu
http://lists.opensuse.org/opensuse-updates/2012-08/msg00023.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1202.htmlhttp://secunia.com/advisories/50118http://secunia.com/advisories/50299http://secunia.com/advisories/50372http://www.openwall.com/lists/oss-security/2012/07/31/4http://www.openwall.com/lists/oss-security/2012/07/31/7http://www.securityfocus.com/bid/54748https://bugzilla.redhat.com/show_bug.cgi?id=844734https://www.redhat.com/archives/libvir-list/2012-July/msg01650.htmlhttp://lists.opensuse.org/opensuse-updates/2012-08/msg00023.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1202.htmlhttp://secunia.com/advisories/50118http://secunia.com/advisories/50299http://secunia.com/advisories/50372http://www.openwall.com/lists/oss-security/2012/07/31/4http://www.openwall.com/lists/oss-security/2012/07/31/7http://www.securityfocus.com/bid/54748https://bugzilla.redhat.com/show_bug.cgi?id=844734https://www.redhat.com/archives/libvir-list/2012-July/msg01650.html
2012-08-07
Published