Resource management error in libvirt - CVE-2011-1486
Published: May 31, 2011 / Updated: August 11, 2020
Vulnerability identifier: #VU45011
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2011-1486
CWE-ID: CWE-399
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vendor: libvirt.org
Affected software:
libvirt
libvirt
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
How to mitigate CVE-2011-1486
Install update from vendor's website.
Sources
- http://libvirt.org/git/?p=libvirt.git;a=commit;h=f44bfb7fb978c9313ce050a1c4149bf04aa0a670
- http://secunia.com/advisories/44459
- http://securitytracker.com/id?1025477
- http://support.avaya.com/css/P8/documents/100134583
- http://www.debian.org/security/2011/dsa-2280
- http://www.redhat.com/support/errata/RHSA-2011-0478.html
- http://www.redhat.com/support/errata/RHSA-2011-0479.html
- http://www.securityfocus.com/bid/47148
- http://www.ubuntu.com/usn/USN-1152-1
- https://bugzilla.redhat.com/show_bug.cgi?id=693391
- https://www.redhat.com/archives/libvir-list/2011-March/msg01087.html