Release date:
Updated on:
Affected Systems:
Libvirt
Description:
--------------------------------------------------------------------------------
Bugtraq id: 62070
The Libvirt library is a Linux API for implementing Linux virtualization. It supports various hypervisors, including Xen and KVM, QEMU, and some virtual products for other operating systems.
The virBitmapParse function of libvirt has a remote denial of service vulnerability when parsing large bitmap strings. Attackers can exploit this vulnerability to cause application crashes in affected libraries.
<* Source: Hao Liu
Link: http://libvirt.org/git? P = libvirt. git; a = commit; h = 0fc89098a68f0f6962de8be4fc03ddd960ffbf08
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Libvirt
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://libvirt.org/index.html
Use libvirt to create and manage KVM virtual machines
Use Libvirt to connect to the KVM virtualization platform
The/bin/qemu-KVM problem cannot be found when the kvm virtual machine is installed with libvirt In Ubuntu.