Candidate: CVE-2013-4400 PublicDate: 2013-12-09 16:36:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4400 https://bugzilla.redhat.com/show_bug.cgi?id=1015228#c3 Description: virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environment variables or command-line arguments. Ubuntu-Description: Notes: mdeslaur> introduced in 1.1.2 Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=727101 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4400 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_libvirt: upstream_libvirt: needs-triage lucid_libvirt: not-affected precise_libvirt: not-affected quantal_libvirt: not-affected raring_libvirt: not-affected saucy_libvirt: not-affected devel_libvirt: not-affected (1.1.1-0ubuntu9)