CVE-2010-3851

libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.7 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
VendorProductVersion
libguestfslibguestfs
𝑥
≤ 1.5.22
libguestfslibguestfs
1.5.0
libguestfslibguestfs
1.5.1
libguestfslibguestfs
1.5.2
libguestfslibguestfs
1.5.3
libguestfslibguestfs
1.5.4
libguestfslibguestfs
1.5.5
libguestfslibguestfs
1.5.6
libguestfslibguestfs
1.5.7
libguestfslibguestfs
1.5.8
libguestfslibguestfs
1.5.9
libguestfslibguestfs
1.5.10
libguestfslibguestfs
1.5.11
libguestfslibguestfs
1.5.12
libguestfslibguestfs
1.5.13
libguestfslibguestfs
1.5.14
libguestfslibguestfs
1.5.15
libguestfslibguestfs
1.5.16
libguestfslibguestfs
1.5.17
libguestfslibguestfs
1.5.18
libguestfslibguestfs
1.5.19
libguestfslibguestfs
1.5.20
libguestfslibguestfs
1.5.21
𝑥
= Vulnerable software versions
References