CVE-2013-0170
published 2013-02-08CVE-2013-0170: Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.77%
92.2th percentile
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libvirt | < libvirt 0.9.12-6 (bookworm) | libvirt 0.9.12-6 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | libvirt | >= 0 < 0.9.12-6 | 0.9.12-6 |
| redhat | libvirt | >= 0 < 0.9.12-6 | 0.9.12-6 |
| redhat | libvirt | >= 0 < 0.9.12-6 | 0.9.12-6 |
| redhat | libvirt | >= 0 < 0.9.12-6 | 0.9.12-6 |
| redhat | libvirt | >= 0.10.2 < 0.10.2.3 | 0.10.2.3 |
| redhat | libvirt | >= 0.9.11 < 0.9.11.9 | 0.9.11.9 |
| redhat | libvirt | >= 0.9.6 < 0.9.6.4 | 0.9.6.4 |
| redhat | libvirt | >= 1.0.0 < 1.0.2 | 1.0.2 |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rhxc-pp54-8x28: Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient
ghsa_unreviewed·2022-05-05
CVE-2013-0170 [MEDIUM] CWE-416 GHSA-rhxc-pp54-8x28: Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.
OSV
CVE-2013-0170: Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient
osv·2013-02-08·CVSS 6.8
CVE-2013-0170 [MEDIUM] CVE-2013-0170: Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.
Ubuntu
libvirt vulnerabilities
vendor_ubuntu·2013-01-29·CVSS 5.0
CVE-2012-4423 [MEDIUM] libvirt vulnerabilities
Title: libvirt vulnerabilities
Summary: libvirt could be made to crash or run programs if it received specially
crafted network traffic.
Wenlong Huang discovered that libvirt incorrectly handled certain RPC
calls. A remote attacker could exploit this and cause libvirt to crash,
resulting in a denial of service. This issue only affected Ubuntu 12.04
LTS. (CVE-2012-4423)
Tingting Zheng discovered that libvirt incorrectly handled cleanup under
certain error conditions. A remote attacker could exploit this and cause
libvirt to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-0170)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libvirt: use-after-free in virNetMessageFree()
vendor_redhat·2013-01-28·CVSS 6.8
CVE-2013-0170 [MEDIUM] CWE-416 libvirt: use-after-free in virNetMessageFree()
libvirt: use-after-free in virNetMessageFree()
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.
Statement: Not vulnerable. This issue did not affect the versions of libvirt as shipped with Red Hat Enterprise Linux 5.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-0170: libvirt - Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserv...
vendor_debian·2013·CVSS 6.8
CVE-2013-0170 [MEDIUM] CVE-2013-0170: libvirt - Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserv...
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.
Scope: local
bookworm: resolved (fixed in 0.9.12-6)
bullseye: resolved (fixed in 0.9.12-6)
forky: resolved (fixed in 0.9.12-6)
sid: resolved (fixed in 0.9.12-6)
trixie: resolved (fixed in 0.9.12-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0170 libvirt: use-after-free in virNetMessageFree() [fedora-all]
bugzilla·2013-01-28·CVSS 6.8
CVE-2013-0170 [MEDIUM] CVE-2013-0170 libvirt: use-after-free in virNetMessageFree() [fedora-all]
CVE-2013-0170 libvirt: use-after-free in virNetMessageFree() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-0170 libvirt: use-after-free in virNetMessageFree()
bugzilla·2013-01-09·CVSS 6.8
CVE-2013-0170 [MEDIUM] CVE-2013-0170 libvirt: use-after-free in virNetMessageFree()
CVE-2013-0170 libvirt: use-after-free in virNetMessageFree()
A flaw was found in the way message freeing on connection cleanup was handled under certain error conditions. A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd or, potentially, escalate their privilages to that of libvirtd process.
Acknowledgements:
This issue was discovered by Tingting Zheng of Red Hat.
Discussion:
Statement:
Not vulnerable. This issue did not affect the versions of libvirt as shipped with Red Hat Enterprise Linux 5.
---
Created libvirt tracking bugs for this issue
Affects: fedora-all [bug 905173]
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0199 https://rhn.redhat.com/errata/RHSA-2013-0199.html
---
Rel
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=46532e3e8ed5f5a736a02f67d6c805492f9ca720http://libvirt.org/news.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098326.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098370.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098398.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00016.htmlhttp://osvdb.org/89644http://rhn.redhat.com/errata/RHSA-2013-0199.htmlhttp://secunia.com/advisories/52001http://secunia.com/advisories/52003http://wiki.libvirt.org/page/Maintenance_Releaseshttp://www.securityfocus.com/bid/57578http://www.securitytracker.com/id/1028047http://www.ubuntu.com/usn/USN-1708-1https://bugzilla.redhat.com/show_bug.cgi?id=893450https://exchange.xforce.ibmcloud.com/vulnerabilities/81552http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=46532e3e8ed5f5a736a02f67d6c805492f9ca720http://libvirt.org/news.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098326.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098370.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-February/098398.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-02/msg00016.htmlhttp://osvdb.org/89644http://rhn.redhat.com/errata/RHSA-2013-0199.htmlhttp://secunia.com/advisories/52001http://secunia.com/advisories/52003http://wiki.libvirt.org/page/Maintenance_Releaseshttp://www.securityfocus.com/bid/57578http://www.securitytracker.com/id/1028047http://www.ubuntu.com/usn/USN-1708-1https://bugzilla.redhat.com/show_bug.cgi?id=893450https://exchange.xforce.ibmcloud.com/vulnerabilities/81552
2013-02-08
Published