CVE-2008-2004
CVE-2008-2004
The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://lists.gnu.org/archive/html/qemu-devel/2008-04/msg00675.htmlhttp://secunia.com/advisories/29129http://secunia.com/advisories/29963http://secunia.com/advisories/30111http://secunia.com/advisories/30717http://secunia.com/advisories/35062https://exchange.xforce.ibmcloud.com/vulnerabilities/42268https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11021http://svn.savannah.gnu.org/viewvc/?view=rev&root=qemu&revision=4277http://www.mandriva.com/security/advisories?name=MDVSA-2008:162http://www.novell.com/linux/security/advisories/2008_13_sr.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0194.html