QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Qemu | Qemu | 0.9.0 (including) | 0.9.0 (including) |
Red Hat Enterprise Linux 5 | RedHat | xen-0:3.0.3-64.el5_2.3 | * |
Kvm | Ubuntu | feisty | * |
Kvm | Ubuntu | gutsy | * |
Kvm | Ubuntu | hardy | * |
Kvm | Ubuntu | intrepid | * |
Qemu | Ubuntu | dapper | * |
Qemu | Ubuntu | feisty | * |
Qemu | Ubuntu | gutsy | * |
Qemu | Ubuntu | hardy | * |
Qemu | Ubuntu | intrepid | * |
Qemu | Ubuntu | jaunty | * |
Xen-3.0 | Ubuntu | feisty | * |
Xen-3.1 | Ubuntu | gutsy | * |
Xen-3.1 | Ubuntu | hardy | * |
Xen-3.1 | Ubuntu | intrepid | * |
Xen-3.2 | Ubuntu | hardy | * |