CVE-2013-4154
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by…
Does this matter?
Lower severity and a low EPSS score (2.20%). Track it; it rarely justifies an emergency change on its own.
Description
The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to "agent based cpu (un)plug," as demonstrated by the "virsh vcpucount foobar --guest" command.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- redhat/libvirt
- Source
- secalert@redhat.com
References
- http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=96518d4316b711c72205117f8d5c967d5127bbb6
- http://libvirt.org/news.html
- http://openwall.com/lists/oss-security/2013/07/19/12Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=984821Exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=986386Patch
- http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=96518d4316b711c72205117f8d5c967d5127bbb6
- http://libvirt.org/news.html
- http://openwall.com/lists/oss-security/2013/07/19/12Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=984821Exploit
- https://bugzilla.redhat.com/show_bug.cgi?id=986386Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.