UBUNTU-CVE-2013-4419

Source
https://ubuntu.com/security/CVE-2013-4419
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-4419.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2013-4419
Related
Published
2013-11-05T20:55:00Z
Modified
2025-04-23T15:01:06Z
Summary
[none]
Details

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.

References

Affected packages

Ubuntu:Pro:16.04:LTS / libguestfs

Package

Name
libguestfs
Purl
pkg:deb/ubuntu/libguestfs@1:1.32.2-4ubuntu2.2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.28.12-1ubuntu2
1:1.28.12-1ubuntu3
1:1.30.6-1ubuntu1
1:1.30.6-1ubuntu2
1:1.32.2-3ubuntu1
1:1.32.2-4ubuntu1
1:1.32.2-4ubuntu2
1:1.32.2-4ubuntu2.2

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:Pro:18.04:LTS / libguestfs

Package

Name
libguestfs
Purl
pkg:deb/ubuntu/libguestfs@1:1.36.13-1ubuntu3.3?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.34.6-7ubuntu1
1:1.36.10-1ubuntu2
1:1.36.10-1ubuntu3
1:1.36.11-1ubuntu1
1:1.36.13-1ubuntu2
1:1.36.13-1ubuntu3
1:1.36.13-1ubuntu3.1
1:1.36.13-1ubuntu3.2
1:1.36.13-1ubuntu3.3

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:20.04:LTS / libguestfs

Package

Name
libguestfs
Purl
pkg:deb/ubuntu/libguestfs@1:1.40.2-7ubuntu5?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.40.2-2ubuntu6
1:1.40.2-2ubuntu8
1:1.40.2-7ubuntu3
1:1.40.2-7ubuntu4
1:1.40.2-7ubuntu5

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:22.04:LTS / libguestfs

Package

Name
libguestfs
Purl
pkg:deb/ubuntu/libguestfs@1:1.46.2-10ubuntu3?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.44.1-1ubuntu6
1:1.44.1-1ubuntu9
1:1.44.1-1ubuntu10
1:1.44.1-1ubuntu11
1:1.46.2-10ubuntu2
1:1.46.2-10ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:24.10 / libguestfs

Package

Name
libguestfs
Purl
pkg:deb/ubuntu/libguestfs@1:1.52.2-3ubuntu2?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.52.0-5ubuntu3
1:1.52.0-6ubuntu1
1:1.52.0-6.1ubuntu1
1:1.52.2-1ubuntu1
1:1.52.2-3ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:24.04:LTS / libguestfs

Package

Name
libguestfs
Purl
pkg:deb/ubuntu/libguestfs@1:1.52.0-5ubuntu3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.50.1-4ubuntu1
1:1.50.1-4ubuntu2
1:1.52.0-2ubuntu1
1:1.52.0-2ubuntu2
1:1.52.0-5ubuntu1
1:1.52.0-5ubuntu2
1:1.52.0-5ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:25.04 / libguestfs

Package

Name
libguestfs
Purl
pkg:deb/ubuntu/libguestfs@1:1.54.1-1ubuntu3?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:1.*

1:1.52.2-3ubuntu2
1:1.52.2-3ubuntu3
1:1.52.2-5ubuntu1
1:1.52.2-6ubuntu1
1:1.52.2-6ubuntu2
1:1.52.2-6ubuntu3
1:1.52.2-7ubuntu1
1:1.54.0-1ubuntu1
1:1.54.1-1ubuntu1
1:1.54.1-1ubuntu2
1:1.54.1-1ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "low"
}