PT-2013-4938 · Red Hat+1 · Libvirt+1

Petr Matousek

·

Published

2013-09-30

·

Updated

2023-02-13

·

CVE-2013-4291

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvirt versions 0.10.2.7, 1.0.5.5, and 1.1.1
Description The issue arises from the virSecurityManagerSetProcessLabel function in libvirt, which fails to properly set group memberships when the domain has read an uid:gid label. This allows local users to gain privileges.
Recommendations For libvirt version 0.10.2.7, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function. For libvirt version 1.0.5.5, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function. For libvirt version 1.1.1, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4291

Affected Products

Suse
Libvirt