3.5

CVE-2012-3445

The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Libvirt Version 0.9.13
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.16% 0.798
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-updates/2012-08/msg00023.html
http://rhn.redhat.com/errata/RHSA-2012-1202.html
http://secunia.com/advisories/50118
Vendor Advisory
http://secunia.com/advisories/50299
http://secunia.com/advisories/50372
http://www.openwall.com/lists/oss-security/2012/07/31/4
http://www.openwall.com/lists/oss-security/2012/07/31/7
http://www.securityfocus.com/bid/54748
https://bugzilla.redhat.com/show_bug.cgi?id=844734
https://www.redhat.com/archives/libvir-list/2012-July/msg01650.html