CVE-2012-3445 PUBLISHED CVSS 3.5 LOW

The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.

EPSS 1.32% · 79.8th percentile

Risk Scores

CVSS v2.0
3.5
EPSS Score
1.32%
79.8th percentile

Affected Products

VendorProductVersions
n/an/an/a
redhatlibvirt0.9.13

Timeline

References

Open in Interactive Console →