Vulnerability Name:

CVE-2011-1486 (CCN-66605)

Assigned:2011-03-23
Published:2011-03-23
Updated:2023-02-13
Summary:libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:3.3 Low (CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P)
2.5 Low (Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
3.3 Low (REDHAT CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P)
2.5 Low (REDHAT Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2011-1486

Source: CCN
Type: libvirt Web site
libvirt: The virtualization API

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: RHSA-2011-0478
Moderate: libvirt security update

Source: CCN
Type: RHSA-2011-0479
Moderate: libvirt security and bug fix update

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: DEBIAN
Type: DSA-2280
libvirt -- several vulnerabilities

Source: CCN
Type: OSVDB ID: 72643
libvirt libvirtd Multiple Thread Error Reporting Remote DoS

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: BID-47148
libvirt Threads Local Denial of Service Vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla Bug 693391
CVE-2011-1486 libvirt: error reporting in libvirtd is not thread safe

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: XF
Type: UNKNOWN
libvirt-threads-dos(66605)

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:rhel_virtualization:5:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:rhel_virtualization:5::server:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:libvirt:libvirt:0.8.2:*:*:*:*:*:*:*
  • AND
  • cpe:/a:redhat:rhel_virtualization:5:*:server:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:6:*:server:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:6:*:workstation:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20111486
    V
    CVE-2011-1486
    2022-05-20
    oval:org.opensuse.security:def:42386
    P
    Security update for ucode-intel (Moderate)
    2022-05-18
    oval:org.opensuse.security:def:42179
    P
    Security update for glib2 (Low)
    2022-04-28
    oval:org.opensuse.security:def:31756
    P
    Security update for apache2 (Important)
    2022-01-12
    oval:org.opensuse.security:def:31325
    P
    Security update for the Linux Kernel (Live Patch 40 for SLE 12 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:31705
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:32222
    P
    Security update for the Linux Kernel (Live Patch 40 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:26159
    P
    Security update for systemd (Moderate)
    2021-11-04
    oval:org.opensuse.security:def:31694
    P
    Security update for util-linux (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:31693
    P
    Security update for MozillaFirefox (Important)
    2021-10-15
    oval:org.opensuse.security:def:33021
    P
    Security update for libqt5-qtsvg (Moderate)
    2021-10-11
    oval:org.opensuse.security:def:33722
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:26124
    P
    Security update for openssl-1_1 (Low)
    2021-09-09
    oval:org.opensuse.security:def:26118
    P
    Security update for php72 (Important)
    2021-09-02
    oval:org.opensuse.security:def:31251
    P
    Security update for unrar (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:26106
    P
    Security update for libmspack (Moderate)
    2021-08-17
    oval:org.opensuse.security:def:33698
    P
    Security update for libcares2 (Important)
    2021-08-16
    oval:org.opensuse.security:def:32161
    P
    Security update for cpio (Important)
    2021-08-14
    oval:org.opensuse.security:def:31664
    P
    Security update for cpio (Important)
    2021-08-14
    oval:org.opensuse.security:def:26098
    P
    Security update for webkit2gtk3 (Important)
    2021-08-03
    oval:org.opensuse.security:def:31240
    P
    Security update for webkit2gtk3 (Important)
    2021-08-03
    oval:org.opensuse.security:def:31239
    P
    Security update for dbus-1 (Important)
    2021-08-02
    oval:org.opensuse.security:def:32147
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-07-21
    oval:org.opensuse.security:def:32943
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:32942
    P
    Security update for ucode-intel (Important)
    2021-06-10
    oval:org.opensuse.security:def:36227
    P
    libvirt-1.2.5-3.76 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42634
    P
    libvirt-1.2.5-3.76 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36499
    P
    libvirt-devel-1.2.5-3.76 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:32112
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:29360
    P
    Security update for avahi (Important)
    2021-06-03
    oval:org.opensuse.security:def:33659
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:32931
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:26060
    P
    Security update for postgresql13 (Moderate)
    2021-05-27
    oval:org.opensuse.security:def:34444
    P
    Security update for postgresql13 (Moderate)
    2021-05-27
    oval:org.opensuse.security:def:26049
    P
    Security update for lz4 (Important)
    2021-05-14
    oval:org.opensuse.security:def:26048
    P
    Security update for the Linux Kernel (Important)
    2021-05-13
    oval:org.opensuse.security:def:26040
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:32904
    P
    Security update for MozillaFirefox (Important)
    2021-04-27
    oval:org.opensuse.security:def:31606
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:34404
    P
    Security update for glibc (Important)
    2021-04-13
    oval:org.opensuse.security:def:32059
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:32060
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:26208
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:32266
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:26202
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:33766
    P
    Security update for screen (Important)
    2021-02-17
    oval:org.opensuse.security:def:28932
    P
    Security update for python (Important)
    2021-02-11
    oval:org.opensuse.security:def:32200
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:28920
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:28921
    P
    Security update for openssh (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:26054
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:26061
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:32930
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:25980
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:32015
    P
    Security update for openssl (Important)
    2020-12-11
    oval:org.opensuse.security:def:32003
    P
    Security update for python-cryptography (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:35979
    P
    libvirt-1.0.5.1-0.7.10 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35772
    P
    libvirt-0.9.6-0.13.42 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:33156
    P
    libjasper on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31849
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:26261
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25733
    P
    Security update for mgetty (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26766
    P
    libsamplerate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33308
    P
    curl-openssl1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31954
    P
    Security update for gstreamer-0_10-plugins-base (Important)
    2020-12-01
    oval:org.opensuse.security:def:26943
    P
    libcap-progs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25871
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32359
    P
    Security update for strongswan (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26824
    P
    sudo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26333
    P
    Security update for redis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25952
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25323
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:31457
    P
    Security update for postgresql91
    2020-12-01
    oval:org.opensuse.security:def:26353
    P
    Security update for tor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32447
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:27497
    P
    libvirt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25776
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:31779
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26474
    P
    Security update for znc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32697
    P
    kvm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25398
    P
    Security update for tigervnc (Critical)
    2020-12-01
    oval:org.opensuse.security:def:26455
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:32513
    P
    freetype2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25788
    P
    Security update for zeromq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29567
    P
    Security update for OpenOffice_org
    2020-12-01
    oval:org.opensuse.security:def:25607
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32056
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26508
    P
    Security update for phpMyAdmin (Important)
    2020-12-01
    oval:org.opensuse.security:def:33190
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31446
    P
    Security update for popt
    2020-12-01
    oval:org.opensuse.security:def:33396
    P
    Security update for SUSE Manager Client Tools (Critical)
    2020-12-01
    oval:org.opensuse.security:def:29655
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26771
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29001
    P
    Security update for Linux kernel
    2020-12-01
    oval:org.opensuse.security:def:25748
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27190
    P
    libicu-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31458
    P
    Security update for postgresql91 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33610
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:29717
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:29218
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25530
    P
    Security update for virglrenderer (Important)
    2020-12-01
    oval:org.opensuse.security:def:26625
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30392
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:26247
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25605
    P
    Security update for MozillaFirefox (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31813
    P
    Security update for apache2-mod_jk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26727
    P
    kdenetwork4-filesharing on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33251
    P
    rsyslog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31905
    P
    Security update for freeradius-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26305
    P
    Security update for python-setuptools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25814
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:32303
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26780
    P
    lvm2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26252
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25899
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31993
    P
    Security update for java-1_7_1-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26978
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25322
    P
    Security update for tigervnc (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25955
    P
    Security update for gstreamer-0_10-plugins-bad (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32408
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27462
    P
    libmusicbrainz-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26390
    P
    Security update for ark (Low)
    2020-12-01
    oval:org.opensuse.security:def:26001
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25334
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:31549
    P
    Security update for screen (Low)
    2020-12-01
    oval:org.opensuse.security:def:26406
    P
    Security update for mbedtls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32469
    P
    Security update for xorg-x11-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25777
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:31911
    P
    Security update for gcc43 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29513
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32736
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25526
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:31900
    P
    Security update for Mozilla Firefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26494
    P
    Security update for pdns-recursor (Important)
    2020-12-01
    oval:org.opensuse.security:def:33151
    P
    libgcrypt11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25852
    P
    Security update for flash-playerqemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:29616
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:26736
    P
    libQtWebKit4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25664
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26552
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31447
    P
    Security update for postgresql94 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33553
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29673
    P
    Security update for dhcpv6
    2020-12-01
    oval:org.opensuse.security:def:29132
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27225
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25529
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:31532
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30355
    P
    Security update for w3m (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29275
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:25541
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26678
    P
    coolkey on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:13975
    P
    USN-1152-1 -- libvirt vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:13022
    P
    DSA-2280-1 libvirt -- several
    2014-06-23
    oval:org.mitre.oval:def:23542
    P
    ELSA-2011:0479: libvirt security and bug fix update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:22520
    P
    ELSA-2011:0478: libvirt security update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:21916
    P
    RHSA-2011:0478: libvirt security update (Moderate)
    2014-02-24
    oval:org.mitre.oval:def:21945
    P
    RHSA-2011:0479: libvirt security and bug fix update (Moderate)
    2014-02-24
    oval:com.redhat.rhsa:def:20110478
    P
    RHSA-2011:0478: libvirt security update (Moderate)
    2011-05-02
    oval:com.redhat.rhsa:def:20110479
    P
    RHSA-2011:0479: libvirt security and bug fix update (Moderate)
    2011-05-02
    BACK
    libvirt libvirt 0.8.2
    redhat rhel virtualization 5
    redhat enterprise linux 6
    redhat enterprise linux 6
    redhat enterprise linux desktop 6
    redhat enterprise linux hpc node 6