CVE Database
/

CVE-2013-4419

Back to search

CVE-2013-4419

Published: Nov 5, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2013:1536
vendor-advisory
x_refsource_REDHAT
55813
third-party-advisory
x_refsource_SECUNIA
SUSE-SU-2013:1626
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now