Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9602

Опубликовано: 26 апр. 2018
Источник: debian

Описание

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qemufixed1:2.8+dfsg-3package
qemu-kvmremovedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1413929

  • The original proposed patch does not fix the issue, cf.

  • https://www.openwall.com/lists/oss-security/2017/01/17/14

  • Upstream patchset: https://lists.gnu.org/archive/html/qemu-devel/2017-01/msg06225.html

  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1035

  • If fixing this issue for older suites, then make sure not to open the

  • CVE-2017-7471 vulnerability and apply as well 9c6b899f7a46893ab3b671e341a2234e9c0c060e

  • See further details in the CVE-2017-7471 tracker entry.

Связанные уязвимости

CVSS3: 7.6
ubuntu
почти 8 лет назад

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

CVSS3: 7.6
redhat
около 9 лет назад

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

CVSS3: 7.6
nvd
почти 8 лет назад

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

CVSS3: 8.8
github
больше 3 лет назад

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

suse-cvrf
больше 8 лет назад

Security update for qemu