8.5
CVSSv2

CVE-2013-4401

Published: 02/11/2013 Updated: 07/11/2023
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

The virConnectDomainXMLToNative API function in libvirt 1.1.0 up to and including 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows malicious users to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 1.1.2

redhat libvirt 1.1.1

redhat libvirt 1.1.0

redhat libvirt 1.1.3

Vendor Advisories

Debian Bug report logs - #727101 libvirt: CVE-2013-4400 / CVE-2013-4401 Package: libvirt; Maintainer for libvirt is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 22 Oct 2013 10:15:01 UTC Severity: important Tags: patch, securi ...
libvirt would allow unintended access privileges ...
The virConnectDomainXMLToNative API function in libvirt 110 through 113 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML NOTE: some of these details are obtained from third party information ...