CVE-2013-4419
published 2013-11-05CVE-2013-4419: The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of…
PriorityP429medium6.8CVSS 2.0
AVAACHAuNCCICAC
EPSS
0.75%
51.3th percentile
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libguestfs | < libguestfs 1:1.22.7-1 (bookworm) | libguestfs 1:1.22.7-1 (bookworm) |
| libguestfs | libguestfs | >= 0 < 1:1.22.7-1 | 1:1.22.7-1 |
| libguestfs | libguestfs | >= 0 < 1:1.22.7-1 | 1:1.22.7-1 |
| libguestfs | libguestfs | >= 0 < 1:1.22.7-1 | 1:1.22.7-1 |
| libguestfs | libguestfs | >= 0 < 1:1.22.7-1 | 1:1.22.7-1 |
| libguestfs | libguestfs | 1.20.0 – 1.20.12 | — |
| libguestfs | libguestfs | 1.22.0 – 1.22.7 | — |
| novell | suse_linux_enterprise_server | — | — |
| suse | suse_linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:A/AC:H/Au:N/C:C/I:C/A:C
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libguestfs: insecure temporary directory handling for guestfish's network socket
vendor_redhat·2013-10-17·CVSS 6.8
CVE-2013-4419 [MEDIUM] CWE-377 libguestfs: insecure temporary directory handling for guestfish's network socket
libguestfs: insecure temporary directory handling for guestfish's network socket
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.
Package: libguestfs (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4419: libguestfs - The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the...
vendor_debian·2013·CVSS 6.8
CVE-2013-4419 [MEDIUM] CVE-2013-4419: libguestfs - The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the...
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.
Scope: local
bookworm: resolved (fixed in 1:1.22.7-1)
bullseye: resolved (fixed in 1:1.22.7-1)
forky: resolved (fixed in 1:1.22.7-1)
sid: resolved (fixed in 1:1.22.7-1)
trixie: resolved (fixed in 1:1.22.7-1)
GHSA
GHSA-3vxx-8f6w-cpxp: The guestfish command in libguestfs 1
ghsa_unreviewed·2022-05-14
CVE-2013-4419 [MEDIUM] GHSA-3vxx-8f6w-cpxp: The guestfish command in libguestfs 1
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.
OSV
CVE-2013-4419: The guestfish command in libguestfs 1
osv·2013-11-05·CVSS 6.8
CVE-2013-4419 [MEDIUM] CVE-2013-4419: The guestfish command in libguestfs 1
The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4419 libguestfs: insecure temporary directory handling for guestfish's network socket [epel-5]
bugzilla·2013-10-18·CVSS 6.8
CVE-2013-4419 [MEDIUM] CVE-2013-4419 libguestfs: insecure temporary directory handling for guestfish's network socket [epel-5]
CVE-2013-4419 libguestfs: insecure temporary directory handling for guestfish's network socket [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2013-4419 libguestfs: insecure temporary directory handling for guestfish's network socket [fedora-all]
bugzilla·2013-10-17·CVSS 6.8
CVE-2013-4419 [MEDIUM] CVE-2013-4419 libguestfs: insecure temporary directory handling for guestfish's network socket [fedora-all]
CVE-2013-4419 libguestfs: insecure temporary directory handling for guestfish's network socket [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
Bugzilla
CVE-2013-4419 libguestfs: insecure temporary directory handling for guestfish's network socket
bugzilla·2013-10-09·CVSS 6.8
CVE-2013-4419 [MEDIUM] CVE-2013-4419 libguestfs: insecure temporary directory handling for guestfish's network socket
CVE-2013-4419 libguestfs: insecure temporary directory handling for guestfish's network socket
libguestfs is a library for accessing and modifying guest disk images. It was found that guestfish, which enables shell scripting and command line access to libguestfs, insecurely created the temporary directory used to store the network socket when started in server mode (using the "--listen" option). If guestfish were run with the "--listen" option, a local attacker could use this flaw to intercept and modify other users' guestfish commands, allowing them to perform arbitrary guestfish actions (such as modifying virtual machines) with the privileges of a different user, or use this flaw to obtain authentication credentials.
Acknowledgements:
This issue was discovered by Michael Scherer of th
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1536.htmlhttp://secunia.com/advisories/55813https://bugzilla.redhat.com/show_bug.cgi?id=1016960https://www.redhat.com/archives/libguestfs/2013-October/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-11/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1536.htmlhttp://secunia.com/advisories/55813https://bugzilla.redhat.com/show_bug.cgi?id=1016960https://www.redhat.com/archives/libguestfs/2013-October/msg00031.html
2013-11-05
Published