Lucene search

K
nvd[email protected]NVD:CVE-2013-4401
HistoryNov 02, 2013 - 6:55 p.m.

CVE-2013-4401

2013-11-0218:55:03
CWE-264
web.nvd.nist.gov
5

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

8.3

Confidence

High

EPSS

0.004

Percentile

73.3%

The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
redhatlibvirtMatch1.1.0
OR
redhatlibvirtMatch1.1.1
OR
redhatlibvirtMatch1.1.2
OR
redhatlibvirtMatch1.1.3

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

8.3

Confidence

High

EPSS

0.004

Percentile

73.3%