MEDIUM
libvirt: insecure calling of polkit
Published Oct 3, 2013
4.6
MEDIUMCVSS 2.0
EPSS 0.40%
Description
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Affected products
No data.
Configuration 1
OR
- 0.9.12
- 0.10.2
- 0.10.2.1
- 0.10.2.2
- 0.10.2.3
- 0.10.2.4
- 0.10.2.5
- 0.10.2.6
- 0.10.2.7
- 1.0.5
- 1.0.5.1
- 1.0.5.2
- 1.0.5.3
- 1.0.5.4
- 1.0.5.5
Configuration 2
OR
- 10.04
- 12.04
- 12.10
- 13.04
Configuration 3
- 6.0
No data.
Red Hat Enterprise Linux 6
libvirt-0:0.10.2-18.el6_4.14
Fixed · RHSA-2013:1272
Red Hat Enterprise Linux 5
libvirt
Not affected
Red Hat Enterprise Linux 7
libvirt
Not affected
Red Hat Storage 2
libvirt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | libvirt-0:0.10.2-18.el6_4.14 | Fixed | RHSA-2013:1272 |
| Red Hat Enterprise Linux 5 | libvirt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libvirt | Not affected | n/a |
| Red Hat Storage 2 | libvirt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://lists.opensuse.org/opensuse-updates/2013-10/msg00023.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-updates/2013-10/msg00024.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2013-1272.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1460.html vendor-advisoryx_refsource_REDHAT
- http://wiki.libvirt.org/page/Maintenance_Releases x_refsource_CONFIRMPatch
- http://www.openwall.com/lists/oss-security/2013/09/18/6 mailing-listx_refsource_MLIST
- http://www.ubuntu.com/usn/USN-1954-1 vendor-advisoryx_refsource_UBUNTUVendor Advisory
- https://access.redhat.com/security/cve/CVE-2013-4311 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1005332 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-4311
- https://www.cve.org/CVERecord?id=CVE-2013-4311
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-updates/2013-10/msg00023.html | vendor-advisoryx_refsource_SUSE | |
| http://lists.opensuse.org/opensuse-updates/2013-10/msg00024.html | vendor-advisoryx_refsource_SUSE | |
| http://rhn.redhat.com/errata/RHSA-2013-1272.html | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| http://rhn.redhat.com/errata/RHSA-2013-1460.html | vendor-advisoryx_refsource_REDHAT | |
| http://wiki.libvirt.org/page/Maintenance_Releases | x_refsource_CONFIRMPatch | |
| http://www.openwall.com/lists/oss-security/2013/09/18/6 | mailing-listx_refsource_MLIST | |
| http://www.ubuntu.com/usn/USN-1954-1 | vendor-advisoryx_refsource_UBUNTUVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2013-4311 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1005332 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-4311 | ||
| https://www.cve.org/CVERecord?id=CVE-2013-4311 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 3, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4311
CISA Vulnrichment
Updated n/a