CVE-2008-1945
LOW severity · CVSS 2.1
2.1CVSS LOW
Summary
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)0%
AV:L/AC:L/Au:N/C:P/I:N/A:N
Affected products we track (2)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlAdvisory
- http://secunia.com/advisories/32063Advisory
- http://secunia.com/advisories/32088Advisory
- http://secunia.com/advisories/34642Advisory
- http://secunia.com/advisories/35031Advisory
- http://secunia.com/advisories/35062Advisory
- http://www.debian.org/security/2009/dsa-1799Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:162Advisory