libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://support.avaya.com/css/P8/documents/100134583 | |
http://secunia.com/advisories/44459 | third party advisory vendor advisory |
http://www.redhat.com/support/errata/RHSA-2011-0479.html | vendor advisory |
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=f44bfb7fb978c9313ce050a1c4149bf04aa0a670 | |
http://securitytracker.com/id?1025477 | vdb entry |
http://www.securityfocus.com/bid/47148 | vdb entry |
http://www.ubuntu.com/usn/USN-1152-1 | vendor advisory |
http://www.redhat.com/support/errata/RHSA-2011-0478.html | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=693391 | patch |
https://www.redhat.com/archives/libvir-list/2011-March/msg01087.html | patch mailing list |
http://www.debian.org/security/2011/dsa-2280 | vendor advisory |