cbcvebase.
CVE-2013-4419
published 2013-11-05

CVE-2013-4419: The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of…

PriorityP429medium6.8CVSS 2.0
AVAACHAuNCCICAC
EPSS
0.75%
51.3th percentile
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibguestfs< libguestfs 1:1.22.7-1 (bookworm)libguestfs 1:1.22.7-1 (bookworm)
libguestfslibguestfs>= 0 < 1:1.22.7-11:1.22.7-1
libguestfslibguestfs>= 0 < 1:1.22.7-11:1.22.7-1
libguestfslibguestfs>= 0 < 1:1.22.7-11:1.22.7-1
libguestfslibguestfs>= 0 < 1:1.22.7-11:1.22.7-1
libguestfslibguestfs1.20.0 – 1.20.12
libguestfslibguestfs1.22.0 – 1.22.7
novellsuse_linux_enterprise_server
susesuse_linux_enterprise_software_development_kit

CVSS provenance

nvdv2.06.8MEDIUMAV:A/AC:H/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.