Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-4401
HistoryNov 02, 2013 - 12:00 a.m.

CVE-2013-4401

2013-11-0200:00:00
ubuntu.com
ubuntu.com
9

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

EPSS

0.004

Percentile

73.3%

The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3
checks for the connect:read permission instead of the connect:write
permission, which allows attackers to gain domain:write privileges and
execute Qemu binaries via crafted XML. NOTE: some of these details are
obtained from third party information.

Bugs

Notes

Author Note
mdeslaur introduced in 1.1.0
OSVersionArchitecturePackageVersionFilename
ubuntu13.10noarchlibvirt< 1.1.1-0ubuntu8.1UNKNOWN

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

EPSS

0.004

Percentile

73.3%