PT-2013-4999 · Red Hat+1 · Libvirt+1

Published

2013-11-02

·

Updated

2024-06-15

·

CVE-2013-4401

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvirt versions 1.1.0 through 1.1.3
Description The issue concerns the virConnectDomainXMLToNative API function, which incorrectly checks for the connect:read permission instead of the connect:write permission. This allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML.
Recommendations For libvirt versions 1.1.0 through 1.1.3, consider restricting access to the virConnectDomainXMLToNative API function until a patch is available. As a temporary workaround, review and limit the use of crafted XML to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1059
CVE-2013-4401
OPENSUSE-SU-2024:10209-1

Affected Products

Alt Linux
Libvirt