Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-47rg-xchh-xj5g

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

EPSS

Процентиль: 29%
0.00105
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

redhat
больше 13 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

nvd
больше 13 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

debian
больше 13 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failur ...

suse-cvrf
больше 12 лет назад

Security update for KVM

EPSS

Процентиль: 29%
0.00105
Низкий