6.9

CVE-2013-4291

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Libvirt Version 0.10.2.7
Redhat ≫ Libvirt Version 1.0.5.5
Redhat ≫ Libvirt Version 1.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.38
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://libvirt.org/news.html
http://wiki.libvirt.org/page/Maintenance_Releases
Patch
http://libvirt.org/git/?p=libvirt.git%3Ba=commitdiff%3Bh=fe11d34a6d46d6641ce90dc665164fda7bb6bff8
https://bugzilla.redhat.com/show_bug.cgi?id=1006509
Patch