Release date:
Updated on: 2013-01-31
Affected Systems:
Libvirt 1.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57578
CVE (CAN) ID: CVE-2013-0170
Libvirt is a free and open-source C function library that supports mainstream virtualization tools in Linux.
Libvirt 1.0.1 and other versions are available in the "virNetMessageFree ()" function (src/rpc/virnetserverclient. c) The released memory can be used to reference the released memory. After successful exploitation, arbitrary code can be executed.
<* Source: Tingting Zheng
Link: http://secunia.com/advisories/52003/
Https://bugzilla.RedHat.com/show_bug.cgi? Id = 893450
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Libvirt
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://libvirt.org/index.html