CVE Vulnerabilities

CVE-2011-2527

Published: Jun 21, 2012 | Modified: Nov 02, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
3.7 MODERATE
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu * 0.14.0 (including)
Qemu Qemu 0.1.0 (including) 0.1.0 (including)
Qemu Qemu 0.1.1 (including) 0.1.1 (including)
Qemu Qemu 0.1.2 (including) 0.1.2 (including)
Qemu Qemu 0.1.3 (including) 0.1.3 (including)
Qemu Qemu 0.1.4 (including) 0.1.4 (including)
Qemu Qemu 0.1.5 (including) 0.1.5 (including)
Qemu Qemu 0.1.6 (including) 0.1.6 (including)
Qemu Qemu 0.2.0 (including) 0.2.0 (including)
Qemu Qemu 0.3.0 (including) 0.3.0 (including)
Qemu Qemu 0.4.0 (including) 0.4.0 (including)
Qemu Qemu 0.4.1 (including) 0.4.1 (including)
Qemu Qemu 0.4.2 (including) 0.4.2 (including)
Qemu Qemu 0.4.3 (including) 0.4.3 (including)
Qemu Qemu 0.6.0 (including) 0.6.0 (including)
Qemu Qemu 0.6.1 (including) 0.6.1 (including)
Qemu Qemu 0.7.0 (including) 0.7.0 (including)
Qemu Qemu 0.7.1 (including) 0.7.1 (including)
Qemu Qemu 0.7.2 (including) 0.7.2 (including)
Qemu Qemu 0.8.0 (including) 0.8.0 (including)
Qemu Qemu 0.8.1 (including) 0.8.1 (including)
Qemu Qemu 0.8.2 (including) 0.8.2 (including)
Qemu Qemu 0.9.0 (including) 0.9.0 (including)
Qemu Qemu 0.9.1 (including) 0.9.1 (including)
Qemu Qemu 0.9.1-5 (including) 0.9.1-5 (including)
Qemu Qemu 0.10.0 (including) 0.10.0 (including)
Qemu Qemu 0.10.1 (including) 0.10.1 (including)
Qemu Qemu 0.10.2 (including) 0.10.2 (including)
Qemu Qemu 0.10.3 (including) 0.10.3 (including)
Qemu Qemu 0.10.4 (including) 0.10.4 (including)
Qemu Qemu 0.10.5 (including) 0.10.5 (including)
Qemu Qemu 0.10.6 (including) 0.10.6 (including)
Qemu Qemu 0.11.0 (including) 0.11.0 (including)
Qemu Qemu 0.11.0-rc0 (including) 0.11.0-rc0 (including)
Qemu Qemu 0.11.0-rc1 (including) 0.11.0-rc1 (including)
Qemu Qemu 0.11.0-rc2 (including) 0.11.0-rc2 (including)
Qemu Qemu 0.11.1 (including) 0.11.1 (including)
Qemu Qemu 0.12.0 (including) 0.12.0 (including)
Qemu Qemu 0.12.0-rc1 (including) 0.12.0-rc1 (including)
Qemu Qemu 0.12.0-rc2 (including) 0.12.0-rc2 (including)
Qemu Qemu 0.12.1 (including) 0.12.1 (including)
Qemu Qemu 0.12.2 (including) 0.12.2 (including)
Qemu Qemu 0.12.3 (including) 0.12.3 (including)
Qemu Qemu 0.12.4 (including) 0.12.4 (including)
Qemu Qemu 0.12.5 (including) 0.12.5 (including)
Qemu Qemu 0.13.0 (including) 0.13.0 (including)
Qemu Qemu 0.13.0-rc0 (including) 0.13.0-rc0 (including)
Qemu Qemu 0.13.0-rc1 (including) 0.13.0-rc1 (including)
Qemu Qemu 0.14.0-rc0 (including) 0.14.0-rc0 (including)
Qemu Qemu 0.14.0-rc1 (including) 0.14.0-rc1 (including)
Qemu Qemu 0.14.0-rc2 (including) 0.14.0-rc2 (including)
Qemu Qemu 0.14.1 (including) 0.14.1 (including)
Qemu Qemu 0.15.0-rc1 (including) 0.15.0-rc1 (including)
Qemu Qemu 0.15.0-rc2 (including) 0.15.0-rc2 (including)
Red Hat Enterprise Linux 6 RedHat qemu-kvm-2:0.12.1.2-2.209.el6 *
Qemu-kvm Ubuntu devel *
Qemu-kvm Ubuntu lucid *
Qemu-kvm Ubuntu maverick *
Qemu-kvm Ubuntu natty *

References