PT-2012-1561 · Qemu+2 · Qemu+2
Andrew Griffiths
·
Publicado
2011-12-05
·
Atualizado
2020-11-02
·
CVE-2011-2527
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Qemu versions 0.14.0 and earlier
Description
The issue arises from the change process uid function in os-posix.c, which fails to properly drop group privileges when the -runas option is used. This allows local guest users to access restricted files on the host.
Recommendations
For Qemu versions 0.14.0 and earlier, consider restricting access to sensitive files on the host until a fixed version is available. As a temporary workaround, avoid using the -runas option to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Qemu
Red Hat
Suse