Description
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9Confidentiality: None
Integrity: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-hr87-j88c-crv5: The remoteClientFreeFunc function in daemon/remote↗2022-05-17 ▶ OSVCVE-2013-4399: The remoteClientFreeFunc function in daemon/remote↗2014-12-12 ▶ CVEListCVE-2013-4399: The remoteClientFreeFunc function in daemon/remote↗2014-12-12 ▶ 📋Vendor Advisories
2Red Hatlibvirt: unprivileged user can crash libvirtd when ACLs are enabled↗2013-09-27 ▶ DebianCVE-2013-4399: libvirt - The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, wh...↗2013 ▶ 💬Community
2BugzillaCVE-2013-4399 libvirt: unprivileged user can crash libvirtd when ACLs are enabled↗2013-10-03 ▶ BugzillaCVE-2013-4399 libvirt: libvirtd will be crashed while destroy the guest which has been connected twice by virt-viewer and enable the access-driver in libvirtd.conf [rhel-7.0]↗2013-09-24 ▶