// For flags

CVE-2013-4419

libguestfs: insecure temporary directory handling for guestfish's network socket

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.

El comando guestfish en libguestfs 1.20.12, 1.22.7 y anteriores versiones, cuando se usa la opción --remote o --listen, no comprueba adecuadamente la propiedad de /tmp/.guestfish-$UID/ al crear un archivo de socket temporal en este directorio, lo que permite a usuarios locales escribir en el socket y ejecutar comandos arbitrarios mediante la creación de /tmp/.guestfish-$UID/ por adelantado.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-06-12 CVE Reserved
  • 2013-11-05 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
  • CWE-377: Insecure Temporary File
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Libguestfs
Search vendor "Libguestfs"
Libguestfs
Search vendor "Libguestfs" for product "Libguestfs"
>= 1.20.0 <= 1.20.12
Search vendor "Libguestfs" for product "Libguestfs" and version " >= 1.20.0 <= 1.20.12"
-
Affected
Libguestfs
Search vendor "Libguestfs"
Libguestfs
Search vendor "Libguestfs" for product "Libguestfs"
>= 1.22.0 <= 1.22.7
Search vendor "Libguestfs" for product "Libguestfs" and version " >= 1.22.0 <= 1.22.7"
-
Affected
Suse
Search vendor "Suse"
Suse Linux Enterprise Software Development Kit
Search vendor "Suse" for product "Suse Linux Enterprise Software Development Kit"
11.0
Search vendor "Suse" for product "Suse Linux Enterprise Software Development Kit" and version "11.0"
sp3
Affected
Novell
Search vendor "Novell"
Suse Linux Enterprise Server
Search vendor "Novell" for product "Suse Linux Enterprise Server"
11.0
Search vendor "Novell" for product "Suse Linux Enterprise Server" and version "11.0"
sp3
Affected