CVE Vulnerabilities

CVE-2013-4401

Published: Nov 02, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
7.4 IMPORTANT
AV:A/AC:M/Au:S/C:C/I:C/A:C
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information.

Affected Software

NameVendorStart VersionEnd Version
LibvirtRedhat1.1.0 (including)1.1.0 (including)
LibvirtRedhat1.1.1 (including)1.1.1 (including)
LibvirtRedhat1.1.2 (including)1.1.2 (including)
LibvirtRedhat1.1.3 (including)1.1.3 (including)
LibvirtUbuntudevel*
LibvirtUbuntusaucy*

References