PT-2018-3399 · Qemu+3 · Qemu+3

Michael Hanselmann

·

Published

2018-06-13

·

Updated

2024-06-15

·

CVE-2018-16872

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: qemu (affected versions not specified)
Description: A flaw in qemu's Media Transfer Protocol (MTP) implementation allows an attacker with write access to the host filesystem shared with a guest to navigate the host filesystem in the context of the QEMU process and read any file the QEMU process has access to. This is due to a TOCTTOU (Time-of-Check-to-Time-of-Use) problem, where the code opening files and directories does not consider that the underlying filesystem may have changed since the time lstat(2) was called. Access to the filesystem may be local or via a network share protocol such as CIFS.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Race Condition

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1973
ALT-PU-2019-1990
BDU:2020-00749
CVE-2018-16872
DLA-1694-1
DSA-4454-1
DSA-4454-2
OPENSUSE-SU-2019:0254-1
OPENSUSE-SU-2019_0254-1
OPENSUSE-SU-2019_1074-1
OPENSUSE-SU-2024:11287-1
SUSE-SU-2019:0423-1
SUSE-SU-2019:0435-1
SUSE-SU-2019:0471-1
SUSE-SU-2019:0471-2
SUSE-SU-2019:0489-1
SUSE-SU-2019:0582-1
SUSE-SU-2019_0423-1
SUSE-SU-2019_0435-1
SUSE-SU-2019_0471-1
SUSE-SU-2019_0471-2
USN-3923-1

Affected Products

Alt Linux
Suse
Ubuntu
Qemu