CVE-2013-4154
published 2013-09-30CVE-2013-4154: The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.20%
80.5th percentile
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.1.0-4 (bookworm) | libvirt 1.1.0-4 (bookworm) |
| redhat | libvirt | <= 1.1.0 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | >= 0 < 1.1.0-4 | 1.1.0-4 |
| redhat | libvirt | >= 0 < 1.1.0-4 | 1.1.0-4 |
| redhat | libvirt | >= 0 < 1.1.0-4 | 1.1.0-4 |
| redhat | libvirt | >= 0 < 1.1.0-4 | 1.1.0-4 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libvirt: crash of libvirtd without guest agent configuration
vendor_redhat·2013-07-16·CVSS 4.3
CVE-2013-4154 [MEDIUM] libvirt: crash of libvirtd without guest agent configuration
libvirt: crash of libvirtd without guest agent configuration
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command.
Statement: Not vulnerable. This issue did not affect the versions of libvirt as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2013-4154: libvirt - The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not...
vendor_debian·2013·CVSS 4.3
CVE-2013-4154 [MEDIUM] CVE-2013-4154: libvirt - The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not...
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command.
Scope: local
bookworm: resolved (fixed in 1.1.0-4)
bullseye: resolved (fixed in 1.1.0-4)
forky: resolved (fixed in 1.1.0-4)
sid: resolved (fixed in 1.1.0-4)
trixie: resolved (fixed in 1.1.0-4)
GHSA
GHSA-99hg-84w9-fwh7: The qemuAgentCommand function in libvirt before 1
ghsa_unreviewed·2022-05-17
CVE-2013-4154 [MEDIUM] GHSA-99hg-84w9-fwh7: The qemuAgentCommand function in libvirt before 1
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command.
OSV
CVE-2013-4154: The qemuAgentCommand function in libvirt before 1
osv·2013-09-30·CVSS 4.3
CVE-2013-4154 [MEDIUM] CVE-2013-4154: The qemuAgentCommand function in libvirt before 1
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command.
No detection rules found.
No public exploits indexed.
Bugzilla
libvirt: CVE-2013-4154 libvirt: crash of libvirtd without guest agent configuration [fedora-all]
bugzilla·2013-07-19·CVSS 4.3
CVE-2013-4154 [MEDIUM] libvirt: CVE-2013-4154 libvirt: crash of libvirtd without guest agent configuration [fedora-all]
libvirt: CVE-2013-4154 libvirt: crash of libvirtd without guest agent configuration [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please n
Bugzilla
CVE-2013-4154 libvirt: crash of libvirtd without guest agent configuration
bugzilla·2013-07-19·CVSS 4.3
CVE-2013-4154 [MEDIUM] CVE-2013-4154 libvirt: crash of libvirtd without guest agent configuration
CVE-2013-4154 libvirt: crash of libvirtd without guest agent configuration
If users haven't configured guest agent then qemuAgentCommand() will dereference a NULL 'mon' pointer.
A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=984821
https://www.redhat.com/archives/libvir-list/2013-July/msg00992.html
Acknowledgements:
This issue was discovered by Alex Jia of Red Hat.
Discussion:
Statement:
Not vulnerable. This issue did not affect the versions of libvirt as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.
---
Upstream fix:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=96518d4316b711c72205117f8d5c967d5127bbb6
---
Created libvirt tracking bugs for this i
http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=96518d4316b711c72205117f8d5c967d5127bbb6http://libvirt.org/news.htmlhttp://openwall.com/lists/oss-security/2013/07/19/12https://bugzilla.redhat.com/show_bug.cgi?id=984821https://bugzilla.redhat.com/show_bug.cgi?id=986386http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=96518d4316b711c72205117f8d5c967d5127bbb6http://libvirt.org/news.htmlhttp://openwall.com/lists/oss-security/2013/07/19/12https://bugzilla.redhat.com/show_bug.cgi?id=984821https://bugzilla.redhat.com/show_bug.cgi?id=986386
2013-09-30
Published