Vulnerability Name:

CVE-2013-4291 (CCN-87600)

Assigned:2013-09-30
Published:2013-09-30
Updated:2023-02-13
Summary:libvirt could allow a local attacker to bypass security restrictions, caused by an error in the virSecurityManagerSetProcessLabel() function when the uid:gid label is parsed by the domain. When the group memberships are not set properly, a local attacker could exploit this vulnerability to bypass security restrictions and gain unauthorized access to the application.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2013-4291

Source: CCN
Type: libvirt Web site
libvirt: The virtualization API

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: CCN
Type: BID-62743
libvirt CVE-2013-4291 Local Security Bypass Vulnerability

Source: CCN
Type: Red Hat Bugzilla Bug 1006509
CVE-2013-4291 libvirt: supplementary groups not adjusted correctly when parsing label

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: XF
Type: UNKNOWN
libvirt-cve20134291-security-bypass(87600)

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:20134291
V
CVE-2013-4291
2022-05-20
oval:org.opensuse.security:def:31705
P
Security update for postgresql, postgresql13, postgresql14 (Important)
2021-11-20
oval:org.opensuse.security:def:31694
P
Security update for util-linux (Moderate)
2021-10-19
oval:org.opensuse.security:def:31693
P
Security update for MozillaFirefox (Important)
2021-10-15
oval:org.opensuse.security:def:26124
P
Security update for openssl-1_1 (Low)
2021-09-09
oval:org.opensuse.security:def:26118
P
Security update for php72 (Important)
2021-09-02
oval:org.opensuse.security:def:32147
P
Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
2021-07-21
oval:org.opensuse.security:def:42634
P
libvirt-1.2.5-3.76 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:36227
P
libvirt-1.2.5-3.76 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:36499
P
libvirt-devel-1.2.5-3.76 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:26060
P
Security update for postgresql13 (Moderate)
2021-05-27
oval:org.opensuse.security:def:26049
P
Security update for lz4 (Important)
2021-05-14
oval:org.opensuse.security:def:26048
P
Security update for the Linux Kernel (Important)
2021-05-13
oval:org.opensuse.security:def:32060
P
Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP3) (Important)
2021-04-07
oval:org.opensuse.security:def:26202
P
Security update for MozillaFirefox (Important)
2021-03-01
oval:org.opensuse.security:def:26061
P
Security update for dovecot22 (Important)
2021-01-04
oval:org.opensuse.security:def:25980
P
Security update for MozillaFirefox (Critical)
2020-12-21
oval:org.opensuse.security:def:32003
P
Security update for python-cryptography (Moderate)
2020-12-04
oval:org.opensuse.security:def:31779
P
Security update for MozillaFirefox (Important)
2020-12-01
oval:org.opensuse.security:def:27462
P
libmusicbrainz-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26508
P
Security update for phpMyAdmin (Important)
2020-12-01
oval:org.opensuse.security:def:32359
P
Security update for strongswan (Moderate)
2020-12-01
oval:org.opensuse.security:def:26474
P
Security update for znc (Moderate)
2020-12-01
oval:org.opensuse.security:def:33190
P
libvirt on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26824
P
sudo on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26494
P
Security update for pdns-recursor (Important)
2020-12-01
oval:org.opensuse.security:def:32303
P
Security update for python (Moderate)
2020-12-01
oval:org.opensuse.security:def:26390
P
Security update for ark (Low)
2020-12-01
oval:org.opensuse.security:def:33151
P
libgcrypt11 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26780
P
lvm2 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26455
P
Security update for chromium (Important)
2020-12-01
oval:org.opensuse.security:def:26333
P
Security update for redis (Moderate)
2020-12-01
oval:org.opensuse.security:def:25852
P
Security update for flash-playerqemu (Important)
2020-12-01
oval:org.opensuse.security:def:32513
P
freetype2 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26766
P
libsamplerate on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26406
P
Security update for mbedtls (Moderate)
2020-12-01
oval:org.opensuse.security:def:26252
P
Security update for mariadb-100 (Moderate)
2020-12-01
oval:org.opensuse.security:def:27225
P
libvirt on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:25788
P
Security update for zeromq (Moderate)
2020-12-01
oval:org.opensuse.security:def:32469
P
Security update for xorg-x11-server (Moderate)
2020-12-01
oval:org.opensuse.security:def:26727
P
kdenetwork4-filesharing on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26353
P
Security update for tor (Moderate)
2020-12-01
oval:org.opensuse.security:def:27190
P
libicu-32bit on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:25777
P
Security update for flash-player (Critical)
2020-12-01
oval:org.opensuse.security:def:32447
P
Security update for xen (Important)
2020-12-01
oval:org.opensuse.security:def:26678
P
coolkey on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:31911
P
Security update for gcc43 (Moderate)
2020-12-01
oval:org.opensuse.security:def:27497
P
libvirt-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26552
P
g3utils on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:25776
P
Security update for flash-player (Critical)
2020-12-01
oval:org.opensuse.security:def:32408
P
Security update for wget (Moderate)
2020-12-01
oval:org.opensuse.security:def:26625
P
pam_ldap on GA media (Moderate)
2020-12-01
oval:org.mitre.oval:def:25621
P
SUSE-SU-2013:1642-1 -- Security update for libvirt
2014-09-08
oval:com.ubuntu.precise:def:20134291000
V
CVE-2013-4291 on Ubuntu 12.04 LTS (precise) - medium.
2013-09-30
BACK