CVE-2013-2124
published 2014-05-27CVE-2013-2124: Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.60%
83.7th percentile
Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libguestfs | < libguestfs 1:1.20.8-1 (bookworm) | libguestfs 1:1.20.8-1 (bookworm) |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
| libguestfs | libguestfs | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-565j-mpfh-22p5: Double free vulnerability in inspect-fs
ghsa_unreviewed·2022-05-17
CVE-2013-2124 [MEDIUM] GHSA-565j-mpfh-22p5: Double free vulnerability in inspect-fs
Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.
OSV
CVE-2013-2124: Double free vulnerability in inspect-fs
osv·2014-05-27·CVSS 4.3
CVE-2013-2124 [MEDIUM] CVE-2013-2124: Double free vulnerability in inspect-fs
Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.
Red Hat
libguestfs: DoS (abort) due to a double free flaw when inspecting certain guest files / images
vendor_redhat·2013-05-28·CVSS 4.3
CVE-2013-2124 [MEDIUM] libguestfs: DoS (abort) due to a double free flaw when inspecting certain guest files / images
libguestfs: DoS (abort) due to a double free flaw when inspecting certain guest files / images
Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.
Statement: Not vulnerable. This issue did not affect the version of libguestfs as shipped with Red Hat Enterprise Linux 6 as it did not include the upstream commit 5a3da366268825b26b470cde35658b67c1d11cd4 that introduced this issue.
Package: libguestfs (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2013-2124: libguestfs - Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1....
vendor_debian·2013·CVSS 4.3
CVE-2013-2124 [MEDIUM] CVE-2013-2124: libguestfs - Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1....
Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.
Scope: local
bookworm: resolved (fixed in 1:1.20.8-1)
bullseye: resolved (fixed in 1:1.20.8-1)
forky: resolved (fixed in 1:1.20.8-1)
sid: resolved (fixed in 1:1.20.8-1)
trixie: resolved (fixed in 1:1.20.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2124 libguestfs: DoS (abort) due to a double free flaw when inspecting certain guest files / images [epel-5]
bugzilla·2013-05-29·CVSS 4.3
CVE-2013-2124 [MEDIUM] CVE-2013-2124 libguestfs: DoS (abort) due to a double free flaw when inspecting certain guest files / images [epel-5]
CVE-2013-2124 libguestfs: DoS (abort) due to a double free flaw when inspecting certain guest files / images [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field
Bugzilla
CVE-2013-2124 libguestfs: DoS (abort) due to a double free flaw when inspecting certain guest files / images
bugzilla·2013-05-29·CVSS 4.3
CVE-2013-2124 [MEDIUM] CVE-2013-2124 libguestfs: DoS (abort) due to a double free flaw when inspecting certain guest files / images
CVE-2013-2124 libguestfs: DoS (abort) due to a double free flaw when inspecting certain guest files / images
A double-free flaw was found in the way Libguestfs, a library for accessing and modifying guest disk images, performed scan of certain guest files / images. A remote attacker could provide a specially-crafted guest file that, when inspected in an application linked against Libguestfs would lead to that application abort (denial of service).
References:
[1] https://www.redhat.com/archives/libguestfs/2013-May/msg00079.html
[2] https://www.redhat.com/archives/libguestfs/2013-May/msg00080.html
Relevant upstream patch (including reproducer):
[3] https://github.com/libguestfs/libguestfs/commit/fa6a76050d82894365dfe32916903ef7fee3ffcd
CVE Request:
[4] http://www.openwall.com/lists/oss-
Bugzilla
CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
bugzilla·2012-04-20·CVSS 5.0
CVE-2012-2124 [MEDIUM] CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
A Red Hat Security Advisory RHSA-2012:0103 for squirrelmail packages shipped in Red Hat Enterprise Linux 4 and 5 claim to have fixed CVE-2010-2813 issue ("CVE-2010-2813 SquirrelMail: DoS (disk space consumption) by random IMAP login attempts with 8-bit characters in the password", bug #618096). However, the patch for this issue was not applied correctly and hence the issue was not fixed as stated in the advisory.
Discussion:
CVE assignment notification:
http://www.openwall.com/lists/oss-security/2012/04/20/22
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0126 https://rhn.redhat.com/errata/RHSA-2013-0126.html
http://osvdb.org/93724http://seclists.org/oss-sec/2013/q2/431http://www.securityfocus.com/bid/60205https://exchange.xforce.ibmcloud.com/vulnerabilities/85145https://github.com/libguestfs/libguestfs/commit/fa6a76050d82894365dfe32916903ef7fee3ffcdhttps://www.redhat.com/archives/libguestfs/2013-May/msg00079.htmlhttps://www.redhat.com/archives/libguestfs/2013-May/msg00080.htmlhttp://osvdb.org/93724http://seclists.org/oss-sec/2013/q2/431http://www.securityfocus.com/bid/60205https://exchange.xforce.ibmcloud.com/vulnerabilities/85145https://github.com/libguestfs/libguestfs/commit/fa6a76050d82894365dfe32916903ef7fee3ffcdhttps://www.redhat.com/archives/libguestfs/2013-May/msg00079.htmlhttps://www.redhat.com/archives/libguestfs/2013-May/msg00080.html
2014-05-27
Published