PT-2013-4938 · Red Hat+1 · Libvirt+1
Petr Matousek
·
Published
2013-09-30
·
Updated
2023-02-13
·
CVE-2013-4291
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libvirt versions 0.10.2.7, 1.0.5.5, and 1.1.1
Description
The issue arises from the virSecurityManagerSetProcessLabel function in libvirt, which fails to properly set group memberships when the domain has read an uid:gid label. This allows local users to gain privileges.
Recommendations
For libvirt version 0.10.2.7, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function.
For libvirt version 1.0.5.5, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function.
For libvirt version 1.1.1, update to a version that fixes the issue with the virSecurityManagerSetProcessLabel function.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suse
Libvirt