CVE-2011-2511

Advisory lineage Upstream: 0 Downstream: 5
Modified
Published: 10 Aug 2011, 20:00
Last modified:06 Aug 2024, 23:00

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4 MEDIUM
v2.0 (nvd)
EPSS Score
3.42% LOW
3% probability +0.58%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Aug 2011, 20:00
Published
Vulnerability first disclosed
06 Aug 2024, 23:00
Last Modified
Vulnerability information updated

Description

Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.

CVSS Metrics

  • v2.0MEDIUMScore: 4AV:N/AC:L/Au:S/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 3.42% Percentile: 88%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • redhatlibvirt

    ≤ 0.9.2 | 0.0.1 | 0.0.2 | 0.0.3 | 0.0.4 | 0.0.5 | 0.0.6 | 0.1.0 | 0.1.1 | 0.1.3 | 0.1.4 | 0.1.5 | 0.1.6 | 0.1.7 | 0.1.8 | 0.1.9 | 0.2.0 | 0.2.1 | 0.2.2 | 0.2.3 | 0.3.0 | 0.3.1 | 0.3.2 | 0.3.3 | 0.4.0 | 0.4.1 | 0.4.2 | 0.4.3 | 0.4.4 | 0.4.5 | 0.4.6 | 0.5.0 | 0.5.1 | 0.6.0 | 0.6.1 | 0.6.2 | 0.6.3 | 0.6.4 | 0.6.5 | 0.7.0 | 0.7.1 | 0.7.2 | 0.7.3 | 0.7.4 | 0.7.5 | 0.7.6 | 0.7.7 | 0.8.0 | 0.8.1 | 0.8.2 | 0.8.3 | 0.8.4 | 0.8.5 | 0.8.6 | 0.8.7 | 0.8.8 | 0.9.0 | 0.9.1

References (15)