CVE-2013-1962Redhat Libvirt vulnerability

CWE-3998 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
3.8%
top 11.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 29
Latest updateMay 17

Description

The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of requests "to list all volumes for the particular pool."

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDredhat/libvirt1.0.5

🔴Vulnerability Details

2
GHSA
GHSA-6vm5-9cgm-26rc: The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 12022-05-17
CVEList
CVE-2013-1962: The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 12013-05-29

📋Vendor Advisories

3
Ubuntu
libvirt vulnerability2013-07-02
Red Hat
libvirt: DoS (max count of open files exhaustion) due sockets leak in the storage pool2013-05-16
Debian
CVE-2013-1962: libvirt - The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager...2013

💬Community

2
Bugzilla
CVE-2013-1962 libvirt: DoS (max count of open files exhaustion) due sockets leak in the storage pool [fedora-all]2013-05-16
Bugzilla
CVE-2013-1962 libvirt: DoS (max count of open files exhaustion) due sockets leak in the storage pool2013-04-17
CVE-2013-1962 — Redhat Libvirt vulnerability | cvebase