Libvirt Security Notice: LSN-2013-0015
Incorrect permissions on XML conversion APIs
Lifecycle
Reported on: |
20131002 |
Published on: |
20131021 |
Fixed on: |
20131021 |
Credits
See also
Description
The virConnectDomainXMLToNative API was mistakenly given
the 'read' permission instead of the 'write' permission. The latter
is required since the conversion process will trigger execution of
user provided binaries whose path is listed in the XML.
Impact
An unprivileged user with the 'connect:read' permission
could cause the libvirtd daemon to execute arbitrary binaries as root
Workaround
Remove the 'connect:read' permission from untrusted users
Affected product: libvirt
Alternative formats:
[xml] [text]