CVE-2012-2652
07.08.2012, 20:55
The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.Enginsight
Vendor | Product | Version |
---|---|---|
qemu | qemu | 1.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
kvm |
| ||||||||||
qemu |
| ||||||||||
qemu-kvm |
|
References