CVE-2013-4400: High severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability
It was reported that virt-login-shell, an suid-root program, did not sanitize its environment variables or command-line interface arguments properly. This could allow a local user to overwrite arbitrary files as root and elevate their privileges.
This vulnerability was introduced in libvirt 1.1.2.
Acknowledgements:
Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for reporting this issue.
Other sources
virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environment variables or command-line arguments.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4400?
CVE-2013-4400 is considered a high severity vulnerability due to its potential to allow local users to gain root privileges.
How do I fix CVE-2013-4400?
To fix CVE-2013-4400, upgrade the libvirt package to version 1.1.4 or later.
What software is affected by CVE-2013-4400?
CVE-2013-4400 affects Red Hat libvirt versions 1.1.2 and 1.1.3.
Can CVE-2013-4400 be exploited remotely?
No, CVE-2013-4400 requires local access to exploit the vulnerability.
What are the potential consequences of CVE-2013-4400 exploitation?
Exploiting CVE-2013-4400 could allow a local user to overwrite arbitrary files, leading to privilege escalation.