PublicDateAtUSN: 2013-09-17 17:00:00 UTC Candidate: CVE-2013-4296 CRD: 2013-09-17 17:00:00 UTC PublicDate: 2013-09-30 21:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4296 https://ubuntu.com/security/notices/USN-1954-1 Description: The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a crafted RPC call. Ubuntu-Description: Notes: mdeslaur> introduced in 0.9.1 by 158ba8730e44b7dd07a21ab90499996c5dec080a Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_libvirt: upstream: http://libvirt.org/git/?p=libvirt.git;a=commit;h=e7f400a110e2e3673b96518170bfea0855dd82c0 upstream_libvirt: needs-triage lucid_libvirt: not-affected (code not present) precise_libvirt: released (0.9.8-2ubuntu17.13) quantal_libvirt: released (0.9.13-0ubuntu12.5) raring_libvirt: released (1.0.2-0ubuntu11.13.04.4) devel_libvirt: released (1.1.1-0ubuntu6)