ALT-PU-2013-1059-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2013-4399
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=8294aa0c1750dcb49d6345cd9bd97bf421580d8b
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=8294aa0c1750dcb49d6345cd9bd97bf421580d8b
- 60895
- 60895
- GLSA-201412-04
- GLSA-201412-04
- http://security.libvirt.org/2013/0013.html
- http://security.libvirt.org/2013/0013.html
- 62972
- 62972
Modified: 2024-11-21
CVE-2013-4400
virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environment variables or command-line arguments.
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=3e2f27e13b94f7302ad948bcacb5e02c859a25fc
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=3e2f27e13b94f7302ad948bcacb5e02c859a25fc
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=8c3586ea755c40d5e01b22cb7b5c1e668cdec994
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=8c3586ea755c40d5e01b22cb7b5c1e668cdec994
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=b7fcc799ad5d8f3e55b89b94e599903e3c092467
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=b7fcc799ad5d8f3e55b89b94e599903e3c092467
- FEDORA-2013-20869
- FEDORA-2013-20869
- 60895
- 60895
- GLSA-201412-04
- GLSA-201412-04
- http://wiki.libvirt.org/page/Maintenance_Releases
- http://wiki.libvirt.org/page/Maintenance_Releases
- https://bugzilla.redhat.com/show_bug.cgi?id=1015228
- https://bugzilla.redhat.com/show_bug.cgi?id=1015228
Modified: 2024-11-21
CVE-2013-4401
The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information.
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=57687fd6bf7f6e1b3662c52f3f26c06ab19dc96c
- http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=57687fd6bf7f6e1b3662c52f3f26c06ab19dc96c
- 55210
- 55210
- 60895
- 60895
- GLSA-201412-04
- GLSA-201412-04
- http://wiki.libvirt.org/page/Maintenance_Releases
- http://wiki.libvirt.org/page/Maintenance_Releases
- 1029241
- 1029241
- USN-2026-1
- USN-2026-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1015259
- https://bugzilla.redhat.com/show_bug.cgi?id=1015259