PT-2013-4938 · Red Hat+1 · Libvirt+1
Petr Matousek
·
Publicado
2013-09-30
·
Atualizado
2023-02-13
·
CVE-2013-4291
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libvirt versions 0.10.2.7, 1.0.5.5, and 1.1.1
Description
The issue arises from the virSecurityManagerSetProcessLabel function in libvirt, which fails to properly set group memberships when the domain has read an uid:gid label. This allows local users to gain privileges.
Recommendations
For libvirt version 0.10.2.7, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function.
For libvirt version 1.0.5.5, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function.
For libvirt version 1.1.1, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Suse
Libvirt