CVE-2013-4297
published 2013-09-30CVE-2013-4297: The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service…
PriorityP416medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.97%
78.2th percentile
The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.
Affected
100 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.1.2-2 (bookworm) | libvirt 1.1.2-2 (bookworm) |
| redhat | libvirt | <= 1.1.2 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libvirt: invalid free in virFileNBDDeviceAssociate
vendor_redhat·2013-09-03·CVSS 4.0
CVE-2013-4297 [MEDIUM] libvirt: invalid free in virFileNBDDeviceAssociate
libvirt: invalid free in virFileNBDDeviceAssociate
The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.
Statement: Not vulnerable.
This issue did not affect the versions of libvirt package as shipped with Red Hat Enterprise Linux 5 and 6.
Package: libvirt (Red Hat Enterprise Linux 5) - Not affected
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4297: libvirt - The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and ea...
vendor_debian·2013·CVSS 4.0
CVE-2013-4297 [MEDIUM] CVE-2013-4297: libvirt - The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and ea...
The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.1.2-2)
bullseye: resolved (fixed in 1.1.2-2)
forky: resolved (fixed in 1.1.2-2)
sid: resolved (fixed in 1.1.2-2)
trixie: resolved (fixed in 1.1.2-2)
GHSA
GHSA-jmvg-q6wm-56j5: The virFileNBDDeviceAssociate function in util/virfile
ghsa_unreviewed·2022-05-17
CVE-2013-4297 [MEDIUM] CWE-119 GHSA-jmvg-q6wm-56j5: The virFileNBDDeviceAssociate function in util/virfile
The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.
OSV
CVE-2013-4297: The virFileNBDDeviceAssociate function in util/virfile
osv·2013-09-30·CVSS 4.0
CVE-2013-4297 [MEDIUM] CVE-2013-4297: The virFileNBDDeviceAssociate function in util/virfile
The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4297 CVE-2013-4291 CVE-2013-5651 libvirt: various flaws [fedora-all]
bugzilla·2013-09-10·CVSS 6.9
CVE-2013-4297 [MEDIUM] CVE-2013-4297 CVE-2013-4291 CVE-2013-5651 libvirt: various flaws [fedora-all]
CVE-2013-4297 CVE-2013-4291 CVE-2013-5651 libvirt: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2013-4297 libvirt: invalid free in virFileNBDDeviceAssociate
bugzilla·2013-09-10·CVSS 4.0
CVE-2013-4297 [MEDIUM] CVE-2013-4297 libvirt: invalid free in virFileNBDDeviceAssociate
CVE-2013-4297 libvirt: invalid free in virFileNBDDeviceAssociate
A potential invalid free (uninialized variable) flaw was found in virFileNBDDeviceAssociate function in libvirt.
A remote user able to issue commands to libvirt daemon could use this flaw to crash libvirtd.
Introduced by:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=8aabd597b379db5ae1655e36dff4f10d5622830a
Upstream fix:
http://libvirt.org/git/?p=libvirt.git;a=commit;h=2dba0323ff0cec31bdcea9dd3b2428af297401f2
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of libvirt package as shipped with Red Hat Enterprise Linux 5 and 6.
---
Created libvirt tracking bugs for this issue:
Affects: fedora-all [bug 1006511]
---
libvirt-1.1.3-2.fc20 has been pushed to the Fedora 20 stable repository
http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=2dba0323ff0cec31bdcea9dd3b2428af297401f2http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4297http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=2dba0323ff0cec31bdcea9dd3b2428af297401f2http://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4297
2013-09-30
Published