rpm package
opensuse/libvirt&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/libvirt&distro=openSUSE%20Tumbleweed
Vulnerabilities (67)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2013-1962 | — | < 2.5.0-1.1 | 2.5.0-1.1 | May 29, 2013 | The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of requests "to list all volumes for the particular pool." | ||
| CVE-2013-0170 | — | < 2.5.0-1.1 | 2.5.0-1.1 | Feb 8, 2013 | Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arb | ||
| CVE-2012-3445 | — | < 2.5.0-1.1 | 2.5.0-1.1 | Aug 7, 2012 | The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers a | ||
| CVE-2011-2511 | — | < 2.5.0-1.1 | 2.5.0-1.1 | Aug 10, 2011 | Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption. | ||
| CVE-2011-1146 | — | < 2.5.0-1.1 | 2.5.0-1.1 | Mar 15, 2011 | libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) | ||
| CVE-2010-2242 | — | < 2.5.0-1.1 | 2.5.0-1.1 | Aug 19, 2010 | Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directo | ||
| CVE-2008-5086 | — | < 7.7.0-2.1 | 7.7.0-2.1 | Dec 19, 2008 | Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions. |
- CVE-2013-1962May 29, 2013affected < 2.5.0-1.1fixed 2.5.0-1.1
The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of requests "to list all volumes for the particular pool."
- CVE-2013-0170Feb 8, 2013affected < 2.5.0-1.1fixed 2.5.0-1.1
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arb
- CVE-2012-3445Aug 7, 2012affected < 2.5.0-1.1fixed 2.5.0-1.1
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers a
- CVE-2011-2511Aug 10, 2011affected < 2.5.0-1.1fixed 2.5.0-1.1
Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.
- CVE-2011-1146Mar 15, 2011affected < 2.5.0-1.1fixed 2.5.0-1.1
libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3)
- CVE-2010-2242Aug 19, 2010affected < 2.5.0-1.1fixed 2.5.0-1.1
Red Hat libvirt 0.2.0 through 0.8.2 creates iptables rules with improper mappings of privileged source ports, which allows guest OS users to bypass intended access restrictions by leveraging IP address and source-port values, as demonstrated by copying and deleting an NFS directo
- CVE-2008-5086Dec 19, 2008affected < 7.7.0-2.1fixed 7.7.0-2.1
Multiple methods in libvirt 0.3.2 through 0.5.1 do not check if a connection is read-only, which allows local users to bypass intended access restrictions and perform administrative actions.
Page 4 of 4