PT-2013-4938 · Red Hat+1 · Libvirt+1

Petr Matousek

·

Publicado

2013-09-30

·

Atualizado

2023-02-13

·

CVE-2013-4291

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvirt versions 0.10.2.7, 1.0.5.5, and 1.1.1
Description The issue arises from the virSecurityManagerSetProcessLabel function in libvirt, which fails to properly set group memberships when the domain has read an uid:gid label. This allows local users to gain privileges.
Recommendations For libvirt version 0.10.2.7, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function. For libvirt version 1.0.5.5, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function. For libvirt version 1.1.1, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4291

Produtos afetados

Suse
Libvirt