CVE-2013-2007

EUVD-2013-1998
The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
qemuqemu
1.4.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
qemu
bookworm
1:7.2+dfsg-7+deb12u7
fixed
bullseye
1:5.2+dfsg-11+deb11u3
fixed
bullseye (security)
1:5.2+dfsg-11+deb11u2
fixed
sid
1:9.1.1+ds-2
fixed
trixie
1:9.1.1+ds-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qemu
lucid
dne
precise
dne
quantal
dne
raring
ignored
saucy
not-affected
qemu-kvm
lucid
not-affected
precise
ignored
quantal
not-affected
raring
dne
saucy
dne
xen
lucid
dne
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
xen-3.3
lucid
not-affected
precise
dne
quantal
dne
raring
dne
saucy
dne
Common Weakness Enumeration