CVE-2013-6456

Description

From CVE.org

The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v2 Score Breakdown

Red HatNVDcve.org
Base Score6.25.8N/A
Attack VectorAdjacent NetworkAdjacent NetworkN/A
Access ComplexityLowMediumN/A
AuthenticationSingleSingleN/A
Confidentiality ImpactNoneNoneN/A
Integrity ImpactPartialPartialN/A
Availability ImpactCompleteCompleteN/A

Vector

Red Hat: AV:A/AC:L/Au:S/C:N/I:P/A:C

NVD: AV:A/AC:M/Au:S/C:N/I:P/A:C

Frequently Asked Questions

Want to get errata notifications? Sign up here.