Bug 1015228 - (CVE-2013-4400) CVE-2013-4400 libvirt: virt-login-shell arbitrary file overwrites vulnerability
CVE-2013-4400 libvirt: virt-login-shell arbitrary file overwrites vulnerability
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 1015247 1025685
  Show dependency treegraph
Reported: 2013-10-03 13:13 EDT by Vincent Danen
Modified: 2015-10-15 14:02 EDT (History)
7 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2013-10-03 13:54:03 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2013-10-03 13:13:00 EDT
It was reported that virt-login-shell, an suid-root program, did not sanitize its environment variables or command-line interface arguments properly.  This could allow a local user to overwrite arbitrary files as root and elevate their privileges.

This vulnerability was introduced in libvirt 1.1.2.


Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for reporting this issue.
Comment 1 Vincent Danen 2013-10-03 13:52:37 EDT

Not vulnerable.

This issue did not affect the versions of libvirt package as shipped with Red Hat Enterprise Linux 5 and 6.
Comment 4 Petr Matousek 2013-11-01 05:43:56 EDT
Created libvirt tracking bugs for this issue:

Affects: fedora-all [bug 1025685]
Comment 5 Fedora Update System 2013-11-11 19:36:10 EST
libvirt- has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.