ID:4076 - Exploit for Resource management error in libvirt - CVE-2013-2218

 
Main Vulnerability Database Exploits ID:4076 - Exploit for Resource management error in libvirt - CVE-2013-2218

ID:4076 - Exploit for Resource management error in libvirt - CVE-2013-2218

Published: August 11, 2020


Vulnerability identifier: #VU42523
Vulnerability risk: Medium
CVE-ID: CVE-2013-2218
CWE-ID: CWE-399
Exploitation vector: Remote access
Vulnerable software:
libvirt

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be skipped, as demonstrated by the "virsh iface-list --inactive" command.


Remediation

Install update from vendor's website.