CVE-2013-6433: High severity Openstack Neutron vulnerability
Kashyap Chamarthy <kchamart> reports:
It's possible for Neutron (OpenStack networking) users to pass arbitrary config files via rootwrap[] which allows privilege escalation by letting user add more exec directories, change configurations of commands using rootwrap, log more than what needs to be done, etc.
Other sources
The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6433?
CVE-2013-6433 is classified as a critical vulnerability due to its potential for privilege escalation.
How do I fix CVE-2013-6433?
To mitigate CVE-2013-6433, upgrade to the latest version of OpenStack Neutron that is not affected by this vulnerability.
Who is affected by CVE-2013-6433?
CVE-2013-6433 affects users of OpenStack Neutron versions from 2013.1 to 2013.2.2.
What types of attacks can CVE-2013-6433 facilitate?
CVE-2013-6433 can facilitate privilege escalation attacks by allowing users to manipulate configurations of rootwrap.
Is there a specific operating system impacted by CVE-2013-6433?
Yes, CVE-2013-6433 impacts OpenStack Neutron installations on Ubuntu versions 13.10 and 14.04.