3.6
CVSSv2

CVE-2013-1766

Published: 20/03/2013 Updated: 21/03/2013
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

libvirt 1.0.2 and previous versions sets the group owner to kvm for device files, which allows local users to write to these files via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 0.9.0

redhat libvirt 0.1.9

redhat libvirt 0.2.0

redhat libvirt 0.1.7

redhat libvirt 0.5.1

redhat libvirt 0.8.0

redhat libvirt 0.5.0

redhat libvirt 0.8.1

redhat libvirt 0.8.4

redhat libvirt 0.4.4

redhat libvirt 0.8.5

redhat libvirt 0.4.3

redhat libvirt 0.8.6

redhat libvirt 0.9.5

redhat libvirt 0.7.3

redhat libvirt 0.9.6

redhat libvirt 0.7.0

redhat libvirt

redhat libvirt 1.0.1

redhat libvirt 1.0.0

redhat libvirt 0.8.8

redhat libvirt 0.2.2

redhat libvirt 0.1.0

redhat libvirt 0.1.1

redhat libvirt 0.0.5

redhat libvirt 0.0.6

redhat libvirt 0.6.3

redhat libvirt 0.6.2

redhat libvirt 0.6.1

redhat libvirt 0.6.0

redhat libvirt 0.0.2

redhat libvirt 0.9.9

redhat libvirt 0.0.1

redhat libvirt 0.9.10

redhat libvirt 0.9.11

redhat libvirt 0.7.4

redhat libvirt 0.9.3

redhat libvirt 0.7.5

redhat libvirt 0.6.5

redhat libvirt 0.9.1

redhat libvirt 0.1.8

redhat libvirt 0.3.0

redhat libvirt 0.1.5

redhat libvirt 0.1.3

redhat libvirt 0.4.6

redhat libvirt 0.4.5

redhat libvirt 0.4.0

redhat libvirt 0.3.2

redhat libvirt 0.4.2

redhat libvirt 0.4.1

redhat libvirt 0.0.3

redhat libvirt 0.7.2

redhat libvirt 0.9.7

redhat libvirt 0.7.6

redhat libvirt 0.7.7

redhat libvirt 0.9.2

redhat libvirt 0.6.4

redhat libvirt 0.9.13

redhat libvirt 0.2.3

redhat libvirt 0.2.1

redhat libvirt 0.1.6

redhat libvirt 0.1.4

redhat libvirt 0.8.2

redhat libvirt 0.8.3

redhat libvirt 0.3.3

redhat libvirt 0.3.1

redhat libvirt 0.8.7

redhat libvirt 0.9.8

redhat libvirt 0.0.4

redhat libvirt 0.9.4

redhat libvirt 0.7.1

redhat libvirt 0.9.12

Vendor Advisories

Debian Bug report logs - #701649 libvirt-bin - libvirtd changes permissions of devices to libvirt-qemu:kvm (CVE-2013-1766) Package: libvirt-bin; Maintainer for libvirt-bin is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Source for libvirt-bin is src:libvirt (PTS, buildd, popcon) Reported by: ...