Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2652

Опубликовано: 28 мая 2012
Источник: redhat
CVSS2: 4.6

Описание

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmAffected
Red Hat Enterprise Linux 6qemu-kvmAffected
Red Hat Enterprise Linux Extended Update Support 6.3qemu-kvmAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=824919qemu: vulnerable to temporary file symlink attacks

4.6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

nvd
больше 13 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

debian
больше 13 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failur ...

github
больше 3 лет назад

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.

suse-cvrf
больше 12 лет назад

Security update for KVM

4.6 Medium

CVSS2