4.6
CVSSv2

CVE-2013-4311

Published: 03/10/2013 Updated: 22/04/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

libvirt 1.0.5.x prior to 1.0.5.6, 0.10.2.x prior to 0.10.2.8, and 0.9.12.x prior to 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 0.10.2.5

redhat libvirt 0.10.2.6

redhat libvirt 1.0.5

redhat libvirt 0.9.12

redhat libvirt 0.10.2

redhat libvirt 0.10.2.1

redhat libvirt 0.10.2.2

redhat libvirt 1.0.5.4

redhat libvirt 1.0.5.3

redhat libvirt 0.10.2.7

redhat libvirt 1.0.5.5

redhat libvirt 0.10.2.3

redhat libvirt 0.10.2.4

redhat libvirt 1.0.5.2

redhat libvirt 1.0.5.1

canonical ubuntu linux 12.04

canonical ubuntu linux 10.04

canonical ubuntu linux 13.04

canonical ubuntu linux 12.10

redhat enterprise linux 6.0

Vendor Advisories

Synopsis Important: libvirt security and bug fix update Type/Severity Security Advisory: Important Topic Updated libvirt packages that fix two security issues and several bugs arenow available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as havingimportant security ...
Several security issues were fixed in libvirt ...
libvirt 105x before 1056, 0102x before 01028, and 0912x before 09122 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288 ...