PT-2013-4999 · Red Hat+1 · Libvirt+1

Publicado

2013-11-02

·

Atualizado

2024-06-15

·

CVE-2013-4401

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvirt versions 1.1.0 through 1.1.3
Description The issue concerns the virConnectDomainXMLToNative API function, which incorrectly checks for the connect:read permission instead of the connect:write permission. This allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML.
Recommendations For libvirt versions 1.1.0 through 1.1.3, consider restricting access to the virConnectDomainXMLToNative API function until a patch is available. As a temporary workaround, review and limit the use of crafted XML to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2013-1059
CVE-2013-4401
OPENSUSE-SU-2024:10209-1

Produtos afetados

Alt Linux
Libvirt