Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2527

Опубликовано: 21 июн. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1

Описание

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.

РелизСтатусПримечание
devel

released

0.14.0+noroms-0ubuntu9
hardy

DNE

lucid

released

0.12.3+noroms-0ubuntu9.15
maverick

released

0.12.5+noroms-0ubuntu7.10
natty

released

0.14.0+noroms-0ubuntu4.4
upstream

needs-triage

Показывать по

EPSS

Процентиль: 26%
0.00088
Низкий

2.1 Low

CVSS2

Связанные уязвимости

redhat
около 14 лет назад

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.

nvd
около 13 лет назад

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.

debian
около 13 лет назад

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earli ...

github
больше 3 лет назад

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.

oracle-oval
больше 13 лет назад

ELSA-2011-1531: qemu-kvm security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 26%
0.00088
Низкий

2.1 Low

CVSS2