First published: Thu Oct 03 2013(Updated: )
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Libvirt | =0.9.12 | |
Red Hat Libvirt | =0.10.2 | |
Red Hat Libvirt | =0.10.2.1 | |
Red Hat Libvirt | =0.10.2.2 | |
Red Hat Libvirt | =0.10.2.3 | |
Red Hat Libvirt | =0.10.2.4 | |
Red Hat Libvirt | =0.10.2.5 | |
Red Hat Libvirt | =0.10.2.6 | |
Red Hat Libvirt | =0.10.2.7 | |
Red Hat Libvirt | =1.0.5 | |
Red Hat Libvirt | =1.0.5.1 | |
Red Hat Libvirt | =1.0.5.2 | |
Red Hat Libvirt | =1.0.5.3 | |
Red Hat Libvirt | =1.0.5.4 | |
Red Hat Libvirt | =1.0.5.5 | |
Ubuntu Linux | =10.04 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =12.10 | |
Ubuntu Linux | =13.04 | |
Red Hat Enterprise Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4311 is classified as a high severity vulnerability allowing local users to bypass intended access restrictions.
To fix CVE-2013-4311, update your libvirt installation to version 1.0.5.6 or later, or to any patched version of 0.10.2 or 0.9.12.
CVE-2013-4311 affects local users of libvirt versions prior to the specified updates, including certain Red Hat and Ubuntu distributions.
CVE-2013-4311 is a race condition vulnerability that allows local privilege escalation through PolkitUnixProcess.
A temporary workaround for CVE-2013-4311 may include disabling the affected services or restricting access to vulnerable binaries until a patch is applied.