CVE-2013-6456

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 15 Apr 2014, 18:00
Last modified:06 Aug 2024, 17:39

Vulnerability Summary

Overall Risk (default)
low
23/100
CVSS Score
5.8 MEDIUM
v2.0 (nvd)
EPSS Score
0.24% LOW
0% probability -0.04%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

15 Apr 2014, 18:00
Published
Vulnerability first disclosed
06 Aug 2024, 17:39
Last Modified
Vulnerability information updated

Description

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.

CVSS Metrics

  • v2.0MEDIUMScore: 5.8AV:A/AC:M/Au:S/C:N/I:P/A:C

EPSS Trends

Current EPSS score: 0.24% Percentile: 47%

Techniques & Countermeasures

  • CWE-59Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Systems

  • fedoraprojectfedora

    20

  • redhatlibvirt

    1.0.1 | 1.0.2 | 1.0.3 | 1.0.4 | 1.0.5 | 1.0.5.1 | 1.0.5.2 | 1.0.5.3 | 1.0.5.4 | 1.0.5.5 | 1.0.5.6 | 1.0.6 | 1.1.0 | 1.1.1 | 1.1.2 | 1.1.3 | 1.1.4 | 1.2.0 | 1.2.1

References (12)