Summary
Daniel P. Berrange discovered that incorrect memory handling in the remoteDispatchDomainMemoryStats() function could lead to denial of service.
The oldstable distribution (squeeze) is not affected.
Solution
For the stable distribution (wheezy), this problem has been fixed in version 0.9.12-11+deb7u4. This update also includes some non-security related bugfixes scheduled for the upcoming Wheezy 7.2 point release.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your libvirt packages.
Insight
Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes).
Affected
libvirt on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2013-4296 -
CVSS Base Score: 4.0
AV:N/AC:L/Au:S/C:N/I:N/A:P
Related Vulnerabilities