CVE-2012-2652
07.08.2012, 20:55
The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.Enginsight
| Vendor | Product | Version |
|---|---|---|
| qemu | qemu | 1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| kvm |
| ||||||||||
| qemu |
| ||||||||||
| qemu-kvm |
|
References