CVE Database
/

CVE-2013-6456

Back to search

CVE-2013-6456

Published: Apr 15, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.

VendorProductVersions

n/a

n/a

affected
n/a

References

http://libvirt.org/news.html
x_refsource_CONFIRM
56187
third-party-advisory
x_refsource_SECUNIA
60895
third-party-advisory
x_refsource_SECUNIA
GLSA-201412-04
vendor-advisory
x_refsource_GENTOO
openSUSE-SU-2014:0593
vendor-advisory
x_refsource_SUSE
FEDORA-2014-2864
vendor-advisory
x_refsource_FEDORA
65743
vdb-entry
x_refsource_BID
56215
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now