CVE-2013-6456

Published Apr 15, 2014

Last updated 2 years ago

Overview

Description
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.
Source
secalert@redhat.com
NVD status
Modified

Risk scores

CVSS 2.0

Type
Primary
Base score
5.8
Impact score
7.8
Exploitability score
4.4
Vector string
AV:A/AC:M/Au:S/C:N/I:P/A:C

Weaknesses

nvd@nist.gov
CWE-59

Social media

Hype score
Not currently trending

Configurations