| Reported on: | 20130104 |
|---|---|
| Published on: | 20130128 |
| Fixed on: | 20130128 |
| Reported by: | Peter Krempa |
|---|---|
| Patched by: | Peter Krempa |
When reading and dispatching of a message failed the message was freed but was not removed from the message queue. When the connection was later closed this would result in an attempt to free uninitialized memory
A malicious user could send an RPC message which intentionally results in an error and thus cause libvirtd to crash
Remove access to libvirtd from untrusted user accounts