Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-47rg-xchh-xj5g

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

EPSS

Процентиль: 27%
0.00344
Низкий

Связанные уязвимости

ubuntu
около 14 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

redhat
около 14 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

nvd
около 14 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

debian
около 14 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failur ...

suse-cvrf
около 13 лет назад

Security update for KVM

EPSS

Процентиль: 27%
0.00344
Низкий