CVE-2012-2652

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.4 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
VendorProductVersion
qemuqemu
1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
qemu
bullseye
1:5.2+dfsg-11+deb11u3
fixed
bullseye (security)
1:5.2+dfsg-11+deb11u2
fixed
bookworm
1:7.2+dfsg-7+deb12u7
fixed
sid
1:9.1.1+ds-2
fixed
trixie
1:9.1.1+ds-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kvm
precise
dne
oneiric
dne
natty
dne
lucid
dne
hardy
ignored
qemu
precise
dne
oneiric
dne
natty
dne
lucid
dne
hardy
ignored
qemu-kvm
precise
Fixed 1.0+noroms-0ubuntu14.1
released
oneiric
Fixed 0.14.1+noroms-0ubuntu6.4
released
natty
Fixed 0.14.0+noroms-0ubuntu4.6
released
lucid
Fixed 0.12.3+noroms-0ubuntu9.19
released
hardy
dne