CVE-2013-4399
published 2014-12-12CVE-2013-4399: The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.08%
79.5th percentile
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
Affected
113 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libvirt | < libvirt 1.1.4-1 (bookworm) | libvirt 1.1.4-1 (bookworm) |
| redhat | libvirt | <= 1.1.3 | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
| redhat | libvirt | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hr87-j88c-crv5: The remoteClientFreeFunc function in daemon/remote
ghsa_unreviewed·2022-05-17
CVE-2013-4399 [MEDIUM] GHSA-hr87-j88c-crv5: The remoteClientFreeFunc function in daemon/remote
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
OSV
CVE-2013-4399: The remoteClientFreeFunc function in daemon/remote
osv·2014-12-12·CVSS 4.3
CVE-2013-4399 [MEDIUM] CVE-2013-4399: The remoteClientFreeFunc function in daemon/remote
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
Red Hat
libvirt: unprivileged user can crash libvirtd when ACLs are enabled
vendor_redhat·2013-09-27·CVSS 4.3
CVE-2013-4399 [MEDIUM] libvirt: unprivileged user can crash libvirtd when ACLs are enabled
libvirt: unprivileged user can crash libvirtd when ACLs are enabled
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
Statement: Not vulnerable.
This issue did not affect the versions of libvirt package as shipped with Red Hat Enterprise Linux 5 and 6.
Package: libvirt (Red Hat Enterprise Linux 6) - Not affected
Package: libvirt (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4399: libvirt - The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, wh...
vendor_debian·2013·CVSS 4.3
CVE-2013-4399 [MEDIUM] CVE-2013-4399: libvirt - The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, wh...
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
Scope: local
bookworm: resolved (fixed in 1.1.4-1)
bullseye: resolved (fixed in 1.1.4-1)
forky: resolved (fixed in 1.1.4-1)
sid: resolved (fixed in 1.1.4-1)
trixie: resolved (fixed in 1.1.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4399 libvirt: unprivileged user can crash libvirtd when ACLs are enabled
bugzilla·2013-10-03·CVSS 4.3
CVE-2013-4399 [MEDIUM] CVE-2013-4399 libvirt: unprivileged user can crash libvirtd when ACLs are enabled
CVE-2013-4399 libvirt: unprivileged user can crash libvirtd when ACLs are enabled
It was discovered that an unprivileged user with read-only access to a libvirt guest could connect to it and, by disconnecting, cause a crash of the guest if the access-driver ACLs were defined in libvirtd.conf. This was due libvirtd not removing event callbacks, which would continue to trigger after the client disconnects, which would cause predictable use of free memory, resulting in a crash.
This vulnerability was introduced in libvirt 1.1.0 and fixed in 1.1.3 [1].
[1] http://libvirt.org/git/?p=libvirt.git;a=commit;h=8294aa0c1750dcb49d6345cd9bd97bf421580d8b
Acknowledgements:
This issue was discovered by Zhenfang Wang of Red Hat.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the
Bugzilla
CVE-2013-4399 libvirt: libvirtd will be crashed while destroy the guest which has been connected twice by virt-viewer and enable the access-driver in libvirtd.conf [rhel-7.0]
bugzilla·2013-09-24·CVSS 4.3
CVE-2013-4399 [MEDIUM] CVE-2013-4399 libvirt: libvirtd will be crashed while destroy the guest which has been connected twice by virt-viewer and enable the access-driver in libvirtd.conf [rhel-7.0]
CVE-2013-4399 libvirt: libvirtd will be crashed while destroy the guest which has been connected twice by virt-viewer and enable the access-driver in libvirtd.conf [rhel-7.0]
commit 8294aa0c1750dcb49d6345cd9bd97bf421580d8b
Author: Daniel P. Berrange
Date: Fri Sep 27 15:46:07 2013 +0100
Fix crash in libvirtd when events are registered & ACLs active
When a client disconnects from libvirtd, all event callbacks
must be removed. This involves running the public API
virConnectDomainEventDeregisterAny
This code does not run in normal API dispatch context, so no
identity was set. The result was that the access control drivers
denied the attempt to deregister callbacks. The callbacks thus
continued to trigger after the client was free'd causing fairly
predictable use of free memory & a crash.
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=8294aa0c1750dcb49d6345cd9bd97bf421580d8bhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2013/0013.htmlhttp://www.securityfocus.com/bid/62972http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=8294aa0c1750dcb49d6345cd9bd97bf421580d8bhttp://secunia.com/advisories/60895http://security.gentoo.org/glsa/glsa-201412-04.xmlhttp://security.libvirt.org/2013/0013.htmlhttp://www.securityfocus.com/bid/62972
2014-12-12
Published