CVE-2010-3851

libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.7 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
libguestfslibguestfs
𝑥
≤ 1.5.22
libguestfslibguestfs
1.5.0
libguestfslibguestfs
1.5.1
libguestfslibguestfs
1.5.2
libguestfslibguestfs
1.5.3
libguestfslibguestfs
1.5.4
libguestfslibguestfs
1.5.5
libguestfslibguestfs
1.5.6
libguestfslibguestfs
1.5.7
libguestfslibguestfs
1.5.8
libguestfslibguestfs
1.5.9
libguestfslibguestfs
1.5.10
libguestfslibguestfs
1.5.11
libguestfslibguestfs
1.5.12
libguestfslibguestfs
1.5.13
libguestfslibguestfs
1.5.14
libguestfslibguestfs
1.5.15
libguestfslibguestfs
1.5.16
libguestfslibguestfs
1.5.17
libguestfslibguestfs
1.5.18
libguestfslibguestfs
1.5.19
libguestfslibguestfs
1.5.20
libguestfslibguestfs
1.5.21
𝑥
= Vulnerable software versions
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
guestfish
RHEL 6
1:1.7.17-17.el6
fixed
libguestfs
RHEL 6
1:1.7.17-17.el6
fixed
libguestfs-devel
RHEL 6
1:1.7.17-17.el6
fixed
libguestfs-java
RHEL 6
1:1.7.17-17.el6
fixed
libguestfs-java-devel
RHEL 6
1:1.7.17-17.el6
fixed
libguestfs-javadoc
RHEL 6
1:1.7.17-17.el6
fixed
libguestfs-mount
RHEL 6
1:1.7.17-17.el6
fixed
libguestfs-tools
RHEL 6
1:1.7.17-17.el6
fixed
libguestfs-tools-c
RHEL 6
1:1.7.17-17.el6
fixed
ocaml-libguestfs
RHEL 6
1:1.7.17-17.el6
fixed
ocaml-libguestfs-devel
RHEL 6
1:1.7.17-17.el6
fixed
perl-Sys-Guestfs
RHEL 6
1:1.7.17-17.el6
fixed
python-libguestfs
RHEL 6
1:1.7.17-17.el6
fixed
ruby-libguestfs
RHEL 6
1:1.7.17-17.el6
fixed
References