CVE-2013-6456
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.
El controlador LXC (lxc/lxc_driver.c) en libvirt 1.0.1 hasta 1.2.1 permite a usuarios locales (1) borrar dispositivos arbitrarios a través de API virDomainDeviceDettach y un ataque symlink en /dev en el contenedor; (2) crear nodos arbitrarios (mknod) a través de la API virDomainDeviceAttach y un ataque symlink en /dev en el contenedor; y causar una denegación de servicio (apagado o reinicio del sistema operativo del host) a través de (3) virDomainShutdown o (4) virDomainReboot API y a un ataque symlink en /dev/initctl en el contenedor, relacionado con "rutas contenidas en /proc/$PID/root" y la función virInitctlSetRunLevel.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-11-04 CVE Reserved
- 2014-04-15 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=5fc590ad9f4 | X_refsource_confirm | |
http://libvirt.org/news.html | X_refsource_confirm | |
http://secunia.com/advisories/60895 | Third Party Advisory | |
http://www.securityfocus.com/bid/65743 | Vdb Entry | |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=732394 | X_refsource_misc | |
https://bugzilla.redhat.com/show_bug.cgi?id=1045643 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2014-February/129199.html | 2023-02-13 | |
http://lists.opensuse.org/opensuse-updates/2014-05/msg00004.html | 2023-02-13 | |
http://secunia.com/advisories/56187 | 2023-02-13 | |
http://secunia.com/advisories/56215 | 2023-02-13 | |
http://security.gentoo.org/glsa/glsa-201412-04.xml | 2023-02-13 | |
http://security.libvirt.org/2013/0018.html | 2023-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.1 Search vendor "Redhat" for product "Libvirt" and version "1.0.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.2 Search vendor "Redhat" for product "Libvirt" and version "1.0.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.3 Search vendor "Redhat" for product "Libvirt" and version "1.0.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.4 Search vendor "Redhat" for product "Libvirt" and version "1.0.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.5 Search vendor "Redhat" for product "Libvirt" and version "1.0.5" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.5.1 Search vendor "Redhat" for product "Libvirt" and version "1.0.5.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.5.2 Search vendor "Redhat" for product "Libvirt" and version "1.0.5.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.5.3 Search vendor "Redhat" for product "Libvirt" and version "1.0.5.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.5.4 Search vendor "Redhat" for product "Libvirt" and version "1.0.5.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.5.5 Search vendor "Redhat" for product "Libvirt" and version "1.0.5.5" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.5.6 Search vendor "Redhat" for product "Libvirt" and version "1.0.5.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.0.6 Search vendor "Redhat" for product "Libvirt" and version "1.0.6" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.1.0 Search vendor "Redhat" for product "Libvirt" and version "1.1.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.1.1 Search vendor "Redhat" for product "Libvirt" and version "1.1.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.1.2 Search vendor "Redhat" for product "Libvirt" and version "1.1.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.1.3 Search vendor "Redhat" for product "Libvirt" and version "1.1.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.1.4 Search vendor "Redhat" for product "Libvirt" and version "1.1.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.2.0 Search vendor "Redhat" for product "Libvirt" and version "1.2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Libvirt Search vendor "Redhat" for product "Libvirt" | 1.2.1 Search vendor "Redhat" for product "Libvirt" and version "1.2.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 20 Search vendor "Fedoraproject" for product "Fedora" and version "20" | - |
Affected
|