CVE-2013-4401

high
Published 2013-11-02 · Modified 2026-04-29
CVSS v3
CVSS v2
8.5
VIR risk
8.5

Description

The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4401

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=1015259

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/55210

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.1.4-1
debian debianbullseyefixed1.1.4-1
debian debianforkyfixed1.1.4-1
debian debiansidfixed1.1.4-1
debian debiantrixiefixed1.1.4-1

Application impact

VendorProductVersionsFixed
redhatlibvirt1.1.0
redhatlibvirt1.1.1
redhatlibvirt1.1.2
redhatlibvirt1.1.3

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.