PT-2013-3472 · Xen+1 · Qemu+1
Daniel Berrange
·
Published
2013-05-13
·
Updated
2024-06-15
·
CVE-2013-1922
CVSS v2.0
3.3
Low
| Vector | AV:L/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
QEMU versions used in Xen 4.2.x
Description
The issue allows local guest OS administrators to read arbitrary files on the host by modifying the header of a raw disk image to identify a different format. This is exploited when the guest is restarted.
Recommendations
For QEMU versions used in Xen 4.2.x, consider restricting access to the raw disk image functionality to minimize the risk of exploitation until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qemu
Suse