5.8
CVSSv2

CVE-2013-6456

Published: 15/04/2014 Updated: 13/02/2023
CVSS v2 Base Score: 5.8 | Impact Score: 7.8 | Exploitability Score: 4.4
VMScore: 516
Vector: AV:A/AC:M/Au:S/C:N/I:P/A:C

Vulnerability Summary

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 up to and including 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat libvirt 1.0.5.4

redhat libvirt 1.0.5.3

redhat libvirt 1.0.5

redhat libvirt 1.0.5.6

redhat libvirt 1.0.4

redhat libvirt 1.2.0

redhat libvirt 1.0.1

redhat libvirt 1.2.1

redhat libvirt 1.1.2

redhat libvirt 1.1.4

redhat libvirt 1.0.6

redhat libvirt 1.0.2

redhat libvirt 1.1.1

redhat libvirt 1.0.5.1

fedoraproject fedora 20

redhat libvirt 1.0.5.2

redhat libvirt 1.0.3

redhat libvirt 1.0.5.5

redhat libvirt 1.1.0

redhat libvirt 1.1.3

Vendor Advisories

Debian Bug report logs - #732394 libvirt-bin: CVE-2013-6456: virsh shutdown does not handle symlinks correctly for LXC Package: libvirt-bin; Maintainer for libvirt-bin is Debian Libvirt Maintainers <pkg-libvirt-maintainers@listsaliothdebianorg>; Source for libvirt-bin is src:libvirt (PTS, buildd, popcon) Reported by: Reco ...
Several security issues were fixed in libvirt ...
The LXC driver (lxc/lxc_driverc) in libvirt 101 through 121 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service ( ...