6.9
CVSSv2

CVE-2013-4291

Published: 30/09/2013 Updated: 13/02/2023
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 0.10.2.7

redhat libvirt 1.1.1

redhat libvirt 1.0.5.5

Vendor Advisories

The virSecurityManagerSetProcessLabel function in libvirt 01027, 1055, and 111, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges ...