Description
libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
Affected products
- RedHat / libvirt0.8.8
- RedHat / libvirt0.0.1 – 0.0.1
- RedHat / libvirt0.0.2 – 0.0.2
- RedHat / libvirt0.0.3 – 0.0.3
- RedHat / libvirt0.0.4 – 0.0.4
- RedHat / libvirt0.0.5 – 0.0.5
- RedHat / libvirt0.0.6 – 0.0.6
- RedHat / libvirt0.1.0 – 0.1.0
- RedHat / libvirt0.1.1 – 0.1.1
- RedHat / libvirt0.1.3 – 0.1.3
- RedHat / libvirt0.1.4 – 0.1.4
- RedHat / libvirt0.1.5 – 0.1.5
- RedHat / libvirt0.1.6 – 0.1.6
- RedHat / libvirt0.1.7 – 0.1.7
- RedHat / libvirt0.1.8 – 0.1.8
- RedHat / libvirt0.1.9 – 0.1.9
- RedHat / libvirt0.2.0 – 0.2.0
- RedHat / libvirt0.2.1 – 0.2.1
- RedHat / libvirt0.2.2 – 0.2.2
- RedHat / libvirt0.2.3 – 0.2.3
- RedHat / libvirt0.3.0 – 0.3.0
- RedHat / libvirt0.3.1 – 0.3.1
- RedHat / libvirt0.3.2 – 0.3.2
- RedHat / libvirt0.3.3 – 0.3.3
- RedHat / libvirt0.4.0 – 0.4.0
- RedHat / libvirt0.4.1 – 0.4.1
- RedHat / libvirt0.4.2 – 0.4.2
- RedHat / libvirt0.4.3 – 0.4.3
- RedHat / libvirt0.4.4 – 0.4.4
- RedHat / libvirt0.4.5 – 0.4.5
- RedHat / libvirt0.4.6 – 0.4.6
- RedHat / libvirt0.5.0 – 0.5.0
- RedHat / libvirt0.5.1 – 0.5.1
- RedHat / libvirt0.6.0 – 0.6.0
- RedHat / libvirt0.6.1 – 0.6.1
- RedHat / libvirt0.6.2 – 0.6.2
- RedHat / libvirt0.6.3 – 0.6.3
- RedHat / libvirt0.6.4 – 0.6.4
- RedHat / libvirt0.6.5 – 0.6.5
- RedHat / libvirt0.7.0 – 0.7.0
- RedHat / libvirt0.7.1 – 0.7.1
- RedHat / libvirt0.7.2 – 0.7.2
- RedHat / libvirt0.7.3 – 0.7.3
- RedHat / libvirt0.7.4 – 0.7.4
- RedHat / libvirt0.7.5 – 0.7.5
- RedHat / libvirt0.7.6 – 0.7.6
- RedHat / libvirt0.7.7 – 0.7.7
- RedHat / libvirt0.8.0 – 0.8.0
- RedHat / libvirt0.8.1 – 0.8.1
- RedHat / libvirt0.8.2 – 0.8.2
- RedHat / libvirt0.8.3 – 0.8.3
- RedHat / libvirt0.8.4 – 0.8.4
- RedHat / libvirt0.8.5 – 0.8.5
- RedHat / libvirt0.8.6 – 0.8.6
- RedHat / libvirt0.8.7 – 0.8.7
References
- MISChttp://support.avaya.com/css/P8/documents/100134583
- VENDOR_ADVISORYhttp://secunia.com/advisories/44459
- MISChttp://www.redhat.com/support/errata/RHSA-2011-0479.html
- MISChttp://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=f44bfb7fb978c9313ce050a1c4149bf04aa0a670
- MISChttp://securitytracker.com/id?1025477
- MISChttp://www.securityfocus.com/bid/47148
- VENDOR_ADVISORYhttp://www.ubuntu.com/usn/USN-1152-1
- MISChttp://www.redhat.com/support/errata/RHSA-2011-0478.html
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=693391
- MISChttps://www.redhat.com/archives/libvir-list/2011-March/msg01087.html
- VENDOR_ADVISORYhttp://www.debian.org/security/2011/dsa-2280