{"schema_version":"1.7.5","id":"CVE-2013-4401","published":"2013-11-02T18:55:03Z","modified":"2026-04-10T03:44:30.296245Z","related":["openSUSE-SU-2024:10209-1"],"details":"The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML.  NOTE: some of these details are obtained from third party information.","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/55210"},{"type":"ADVISORY","url":"http://secunia.com/advisories/60895"},{"type":"ADVISORY","url":"http://security.gentoo.org/glsa/glsa-201412-04.xml"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2026-1"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1015259"},{"type":"WEB","url":"http://libvirt.org/git/?p=libvirt.git%3Ba=commit%3Bh=57687fd6bf7f6e1b3662c52f3f26c06ab19dc96c"},{"type":"WEB","url":"http://wiki.libvirt.org/page/Maintenance_Releases"},{"type":"WEB","url":"http://www.securitytracker.com/id/1029241"}]}