Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 358877 (CVE-2011-1146) - <app-emulation/libvirt-0.8.8-r1: Server DoS w/read-only connection (CVE-2011-1146)
Summary: <app-emulation/libvirt-0.8.8-r1: Server DoS w/read-only connection (CVE-2011-...
Status: RESOLVED FIXED
Alias: CVE-2011-1146
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: http://libvirt.org/git/?p=libvirt.git...
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-03-14 14:10 UTC by Alex Legler (RETIRED)
Modified: 2012-02-27 22:32 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alex Legler (RETIRED) archtester gentoo-dev Security 2011-03-14 14:10:22 UTC
From https://bugzilla.redhat.com/show_bug.cgi?id=683650:
It has been found that several libvirt API calls (virNodeDeviceDettach,
virNodeDeviceReset, virDomainRevertToSnapshot, virDomainSnapshotDelete) did not
honour read-only connection. Remote attacker could use this flaw to crash the
host server (DoS).

Patch (applied upstream): see $URL
Comment 1 Diego Elio Pettenò (RETIRED) gentoo-dev 2011-03-14 14:31:48 UTC
0.8.8-r1 in tree.
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-03-15 04:00:53 UTC
(In reply to comment #1)
> 0.8.8-r1 in tree.

Thank you.

Arches, please test and mark stable:
=app-emulation/libvirt-0.8.8-r1
Target keywords : "amd64 x86"
Comment 3 Agostino Sarubbo gentoo-dev 2011-03-15 12:29:48 UTC
amd64 ok
Comment 4 Markos Chandras (RETIRED) gentoo-dev 2011-03-15 15:19:58 UTC
amd64 done. Thanks Agostino
Comment 5 Thomas Kahle (RETIRED) gentoo-dev 2011-03-17 23:23:36 UTC
x86 stable.
Comment 6 Tim Sammut (RETIRED) gentoo-dev 2011-03-19 22:36:42 UTC
Thanks, folks.

GLSA Vote: yes.
Comment 7 Stefan Behte (RETIRED) gentoo-dev Security 2011-03-29 20:01:40 UTC
Yes, too.

GLSA request filed.
Comment 8 GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 00:27:00 UTC
CVE-2011-1146 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1146):
  libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict
  operations in a read-only connection, which allows remote attackers to cause
  a denial of service (host OS crash) or possibly execute arbitrary code via a
  (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3)
  virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5)
  virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different
  vulnerability than CVE-2008-5086.
Comment 9 Doug Goldstein (RETIRED) gentoo-dev 2012-02-09 19:25:52 UTC
Affected versions are no longer in tree.
Comment 10 GLSAMaker/CVETool Bot gentoo-dev 2012-02-27 22:32:49 UTC
This issue was resolved and addressed in
 GLSA 201202-07 at http://security.gentoo.org/glsa/glsa-201202-07.xml
by GLSA coordinator Stefan Behte (craig).