cbcvebase.
CVE-2013-4401
published 2013-11-02

CVE-2013-4401: The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission…

high8.5CVSS 3.1
AVNACMAuSCCICAC
The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibvirt< libvirt 1.1.4-1 (bookworm)libvirt 1.1.4-1 (bookworm)
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt
redhatlibvirt>= 0 < 1.1.4-11.1.4-1
redhatlibvirt>= 0 < 1.1.4-11.1.4-1
redhatlibvirt>= 0 < 1.1.4-11.1.4-1
redhatlibvirt>= 0 < 1.1.4-11.1.4-1

CVSS provenance

nvd8.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv8.5HIGH