Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Gentoo: GLSA-201309-18 Normal: Libvirt Remote Code Execution and DoS

gentoo
Calendar Grey September 25, 2013
Dist Gentoo Esm H88
Numerous security flaws in libvirt enable unauthorized remote execution of code and potential Denial of Service attacks; it's imperative to update to the latest secure version without delay.
Multiple vulnerabilities have been found in libvirt, allowing remote attackers to execute arbitrary code or cause Denial of Service.

Summary

An error in the virNetMessageFree() function in rpc/virnetserverclient.c can lead to a use-after-free. Additionally, a socket leak in the remoteDispatchStoragePoolListAllVolumes command can lead to file descriptor exhaustion.

Resolution

All libvirt users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v ">=app-emulation/libvirt-1.0.5.1-r3"

References

[ 1 ] CVE-2013-0170 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0170 [ 2 ] CVE-2013-1962 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1962

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201309-18
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity: Normal
Title: libvirt: Multiple vulnerabilities
Date: September 25, 2013
Bugs: #454588, #470096
ID: 201309-18

Synopsis

Multiple vulnerabilities have been found in libvirt, allowing remote attackers to execute arbitrary code or cause Denial of Service.

Background

libvirt is a C toolkit for manipulating virtual machines.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-emulation/libvirt < 1.0.5.1-r3 >= 1.0.5.1-r3

Impact

===== A remote attacker could cause certain errors during an RPC connection to cause a message to be freed without being removed from the message queue, possibly resulting in execution of arbitrary code or a Denial of Service condition. Additionally, a remote attacker could repeatedly issue the command to list all pool volumes, causing a Denial of Service condition.

Workaround

There is no known workaround at this time.

Your message here