PT-2012-4162 · Qemu · Qemu

Published

2012-08-07

·

Updated

2023-02-13

·

CVE-2012-2652

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Qemu version 1.0
Description The issue arises from the bdrv open function in Qemu, which fails to properly handle the failure of the mkstemp function when in snapshot node. This allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.
Recommendations For Qemu version 1.0, consider restricting access to the bdrv open function until a patch is available, or apply configuration changes to prevent local users from exploiting the mkstemp function failure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2012-2652
DSA-2542-1
DSA-2545-1
SUSE-SU-2015:0929-1
SUSE-SU-2015:0943-1

Affected Products

Qemu