Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2013-4401

Published: November 2, 2013Last modified: November 10, 2023

Description

The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibvirtNot affected (8.9.0-r5)
StreamlibvirtNot affected (9.6.0-r0)

References

ON THIS PAGE