PT-2012-4162 · Qemu · Qemu

CVE-2012-2652

·

Publicado

2012-08-07

·

Atualizado

2023-02-13

CVSS v2.0

4.4

Média

VetorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Qemu version 1.0
Description The issue arises from the bdrv open function in Qemu, which fails to properly handle the failure of the mkstemp function when in snapshot node. This allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.
Recommendations For Qemu version 1.0, consider restricting access to the bdrv open function until a patch is available, or apply configuration changes to prevent local users from exploiting the mkstemp function failure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-2652
DSA-2542-1
DSA-2545-1
SUSE-SU-2015:0929-1
SUSE-SU-2015:0943-1

Produtos afetados

Qemu