CVE-2011-1486
Vulnerability Summary
Timeline
Description
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
CVSS Metrics
- v2.0•LOW•Score: 3.3AV:A/AC:L/Au:N/C:N/I:N/A:P
EPSS Trends
Current EPSS score: 0.86%• Percentile: 75%
Techniques & Countermeasures
- CWE-399•Resource Management Errors
Weaknesses in this category are related to improper management of system resources.
Affected Systems
- redhat•libvirt
≤ 0.8.8 | 0.0.1 | 0.0.2 | 0.0.3 | 0.0.4 | 0.0.5 | 0.0.6 | 0.1.0 | 0.1.1 | 0.1.3 | 0.1.4 | 0.1.5 | 0.1.6 | 0.1.7 | 0.1.8 | 0.1.9 | 0.2.0 | 0.2.1 | 0.2.2 | 0.2.3 | 0.3.0 | 0.3.1 | 0.3.2 | 0.3.3 | 0.4.0 | 0.4.1 | 0.4.2 | 0.4.3 | 0.4.4 | 0.4.5 | 0.4.6 | 0.5.0 | 0.5.1 | 0.6.0 | 0.6.1 | 0.6.2 | 0.6.3 | 0.6.4 | 0.6.5 | 0.7.0 | 0.7.1 | 0.7.2 | 0.7.3 | 0.7.4 | 0.7.5 | 0.7.6 | 0.7.7 | 0.8.0 | 0.8.1 | 0.8.2 | 0.8.3 | 0.8.4 | 0.8.5 | 0.8.6 | 0.8.7
References (11)
- http://support.avaya.com/css/P8/documents/100134583
- http://secunia.com/advisories/44459
- http://www.redhat.com/support/errata/RHSA-2011-0479.html
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=f44bfb7fb978c9313ce050a1c4149bf04aa0a670
- http://securitytracker.com/id?1025477
- http://www.securityfocus.com/bid/47148
- http://www.ubuntu.com/usn/USN-1152-1
- http://www.redhat.com/support/errata/RHSA-2011-0478.html
- https://bugzilla.redhat.com/show_bug.cgi?id=693391
- https://www.redhat.com/archives/libvir-list/2011-March/msg01087.html
- http://www.debian.org/security/2011/dsa-2280