// For flags

CVE-2013-6456

Gentoo Linux Security Advisory 201412-04

Severity Score

7.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.

El controlador LXC (lxc/lxc_driver.c) en libvirt 1.0.1 hasta 1.2.1 permite a usuarios locales (1) borrar dispositivos arbitrarios a través de API virDomainDeviceDettach y un ataque symlink en /dev en el contenedor; (2) crear nodos arbitrarios (mknod) a través de la API virDomainDeviceAttach y un ataque symlink en /dev en el contenedor; y causar una denegación de servicio (apagado o reinicio del sistema operativo del host) a través de (3) virDomainShutdown o (4) virDomainReboot API y a un ataque symlink en /dev/initctl en el contenedor, relacionado con "rutas contenidas en /proc/$PID/root" y la función virInitctlSetRunLevel.

The LXC driver in libvirt 1.0.1 through 1.2.1 allows local users to delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the virDomainReboot API and a symlink attack on /dev/initctl in the container, related to paths under /proc//root and the virInitctlSetRunLevel function. libvirt was patched to prevent expansion of entities when parsing XML files. This vulnerability allowed malicious users to read arbitrary files or cause a denial of service. The updated packages have been upgraded to the 1.1.3.5 version and patched to correct these issues.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-11-04 CVE Reserved
  • 2014-04-15 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.1
Search vendor "Redhat" for product "Libvirt" and version "1.0.1"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.2
Search vendor "Redhat" for product "Libvirt" and version "1.0.2"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.3
Search vendor "Redhat" for product "Libvirt" and version "1.0.3"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.4
Search vendor "Redhat" for product "Libvirt" and version "1.0.4"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.5
Search vendor "Redhat" for product "Libvirt" and version "1.0.5"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.5.1
Search vendor "Redhat" for product "Libvirt" and version "1.0.5.1"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.5.2
Search vendor "Redhat" for product "Libvirt" and version "1.0.5.2"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.5.3
Search vendor "Redhat" for product "Libvirt" and version "1.0.5.3"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.5.4
Search vendor "Redhat" for product "Libvirt" and version "1.0.5.4"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.5.5
Search vendor "Redhat" for product "Libvirt" and version "1.0.5.5"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.5.6
Search vendor "Redhat" for product "Libvirt" and version "1.0.5.6"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.0.6
Search vendor "Redhat" for product "Libvirt" and version "1.0.6"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.1.0
Search vendor "Redhat" for product "Libvirt" and version "1.1.0"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.1.1
Search vendor "Redhat" for product "Libvirt" and version "1.1.1"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.1.2
Search vendor "Redhat" for product "Libvirt" and version "1.1.2"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.1.3
Search vendor "Redhat" for product "Libvirt" and version "1.1.3"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.1.4
Search vendor "Redhat" for product "Libvirt" and version "1.1.4"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.2.0
Search vendor "Redhat" for product "Libvirt" and version "1.2.0"
-
Affected
Redhat
Search vendor "Redhat"
Libvirt
Search vendor "Redhat" for product "Libvirt"
1.2.1
Search vendor "Redhat" for product "Libvirt" and version "1.2.1"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
20
Search vendor "Fedoraproject" for product "Fedora" and version "20"
-
Affected