CVE-2013-4369
published 2013-10-17CVE-2013-4369: The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by…
PriorityP47low1.9CVSS 2.0
AVLACMAuNCNINAP
EPSS
0.34%
26.5th percentile
The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xen | < xen 4.4.0-1 (bookworm) | xen 4.4.0-1 (bookworm) |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | — | — |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
| xen | xen | >= 0 < 4.4.0-1 | 4.4.0-1 |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen: possible null dereference when parsing vif ratelimiting info (XSA-68)
vendor_redhat·2013-10-10·CVSS 1.9
CVE-2013-4369 [LOW] CWE-476 xen: possible null dereference when parsing vif ratelimiting info (XSA-68)
xen: possible null dereference when parsing vif ratelimiting info (XSA-68)
The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.
Statement: Not vulnerable.
This issue does not affect the versions of the xen package as shipped with Red Hat Enterprise Linux 5 as it does not provide support for the libxl toolstack.
This issue does not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-4369: xen - The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x all...
vendor_debian·2013·CVSS 1.9
CVE-2013-4369 [LOW] CVE-2013-4369: xen - The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x all...
The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
GHSA
GHSA-hh3w-5666-ggp2: The xlu_vif_parse_rate function in the libxlu library in Xen 4
ghsa_unreviewed·2022-05-17
CVE-2013-4369 [LOW] GHSA-hh3w-5666-ggp2: The xlu_vif_parse_rate function in the libxlu library in Xen 4
The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.
OSV
CVE-2013-4369: The xlu_vif_parse_rate function in the libxlu library in Xen 4
osv·2013-10-17·CVSS 1.9
CVE-2013-4369 [LOW] CVE-2013-4369: The xlu_vif_parse_rate function in the libxlu library in Xen 4
The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4371 CVE-2013-4370 CVE-2013-4368 CVE-2013-4369 CVE-2013-4375 xen: various flaws [fedora-all]
bugzilla·2013-10-10·CVSS 1.9
CVE-2013-4371 [LOW] CVE-2013-4371 CVE-2013-4370 CVE-2013-4368 CVE-2013-4369 CVE-2013-4375 xen: various flaws [fedora-all]
CVE-2013-4371 CVE-2013-4370 CVE-2013-4368 CVE-2013-4369 CVE-2013-4375 xen: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Ple
Bugzilla
CVE-2013-4369 xen: possible null dereference when parsing vif ratelimiting info (XSA-68)
bugzilla·2013-09-26·CVSS 1.9
CVE-2013-4369 [LOW] CVE-2013-4369 xen: possible null dereference when parsing vif ratelimiting info (XSA-68)
CVE-2013-4369 xen: possible null dereference when parsing vif ratelimiting info (XSA-68)
The libxlu library function xlu_vif_parse_rate does not properly
handle inputs which consist solely of the '@' character, leading to a
NULL pointer dereference.
A toolstack which allows untrusted users to specify an arbitrary
configuration for the VIF rate can be subjected to a DOS.
The only known user of this library is the xl toolstack which does not
have a central long running daemon and therefore the impact is limited
to crashing the process which is creating the domain, which exists
only to service a single domain.
Acknowledgements:
Red Hat would like to thank the Xen project for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue does not affect the versions of the x
http://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2013/10/10/11https://exchange.xforce.ibmcloud.com/vulnerabilities/87798http://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://www.openwall.com/lists/oss-security/2013/10/10/11https://exchange.xforce.ibmcloud.com/vulnerabilities/87798
2013-10-17
Published