{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-01-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"FEDORA-2013-1626","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098398.html"},{"name":"openSUSE-SU-2013:0275","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00002.html"},{"name":"89644","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/89644"},{"tags":["x_refsource_CONFIRM"],"url":"http://libvirt.org/news.html"},{"name":"libvirt-virnetmessagefree-code-exec(81552)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/81552"},{"name":"openSUSE-SU-2013:0274","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00001.html"},{"name":"SUSE-SU-2013:0320","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00016.html"},{"name":"FEDORA-2013-1644","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098326.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiki.libvirt.org/page/Maintenance_Releases"},{"name":"1028047","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1028047"},{"name":"USN-1708-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1708-1"},{"name":"FEDORA-2013-1642","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098370.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=46532e3e8ed5f5a736a02f67d6c805492f9ca720"},{"name":"52001","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/52001"},{"name":"RHSA-2013:0199","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0199.html"},{"name":"57578","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/57578"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=893450"},{"name":"52003","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/52003"}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-06T14:18:09.230Z"},"title":"CVE Program Container","references":[{"name":"FEDORA-2013-1626","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098398.html"},{"name":"openSUSE-SU-2013:0275","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00002.html"},{"name":"89644","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/89644"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://libvirt.org/news.html"},{"name":"libvirt-virnetmessagefree-code-exec(81552)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/81552"},{"name":"openSUSE-SU-2013:0274","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00001.html"},{"name":"SUSE-SU-2013:0320","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00016.html"},{"name":"FEDORA-2013-1644","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098326.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiki.libvirt.org/page/Maintenance_Releases"},{"name":"1028047","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1028047"},{"name":"USN-1708-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1708-1"},{"name":"FEDORA-2013-1642","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098370.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=46532e3e8ed5f5a736a02f67d6c805492f9ca720"},{"name":"52001","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/52001"},{"name":"RHSA-2013:0199","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2013-0199.html"},{"name":"57578","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/57578"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=893450"},{"name":"52003","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/52003"}]}]},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2013-0170","datePublished":"2013-02-08T20:00:00.000Z","dateReserved":"2012-12-06T00:00:00.000Z","dateUpdated":"2024-08-06T14:18:09.230Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}