CVE Vulnerabilities

CVE-2011-2527

Published: Jun 21, 2012 | Modified: Nov 02, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu * 0.14.0 (including)
Qemu Qemu 0.1.0 (including) 0.1.0 (including)
Qemu Qemu 0.1.1 (including) 0.1.1 (including)
Qemu Qemu 0.1.2 (including) 0.1.2 (including)
Qemu Qemu 0.1.3 (including) 0.1.3 (including)
Qemu Qemu 0.1.4 (including) 0.1.4 (including)
Qemu Qemu 0.1.5 (including) 0.1.5 (including)
Qemu Qemu 0.1.6 (including) 0.1.6 (including)
Qemu Qemu 0.2.0 (including) 0.2.0 (including)
Qemu Qemu 0.3.0 (including) 0.3.0 (including)
Qemu Qemu 0.4.0 (including) 0.4.0 (including)
Qemu Qemu 0.4.1 (including) 0.4.1 (including)
Qemu Qemu 0.4.2 (including) 0.4.2 (including)
Qemu Qemu 0.4.3 (including) 0.4.3 (including)
Qemu Qemu 0.6.0 (including) 0.6.0 (including)
Qemu Qemu 0.6.1 (including) 0.6.1 (including)
Qemu Qemu 0.7.0 (including) 0.7.0 (including)
Qemu Qemu 0.7.1 (including) 0.7.1 (including)
Qemu Qemu 0.7.2 (including) 0.7.2 (including)
Qemu Qemu 0.8.0 (including) 0.8.0 (including)
Qemu Qemu 0.8.1 (including) 0.8.1 (including)
Qemu Qemu 0.8.2 (including) 0.8.2 (including)
Qemu Qemu 0.9.0 (including) 0.9.0 (including)
Qemu Qemu 0.9.1 (including) 0.9.1 (including)
Qemu Qemu 0.9.1-5 (including) 0.9.1-5 (including)
Qemu Qemu 0.10.0 (including) 0.10.0 (including)
Qemu Qemu 0.10.1 (including) 0.10.1 (including)
Qemu Qemu 0.10.2 (including) 0.10.2 (including)
Qemu Qemu 0.10.3 (including) 0.10.3 (including)
Qemu Qemu 0.10.4 (including) 0.10.4 (including)
Qemu Qemu 0.10.5 (including) 0.10.5 (including)
Qemu Qemu 0.10.6 (including) 0.10.6 (including)
Qemu Qemu 0.11.0 (including) 0.11.0 (including)
Qemu Qemu 0.11.0-rc0 (including) 0.11.0-rc0 (including)
Qemu Qemu 0.11.0-rc1 (including) 0.11.0-rc1 (including)
Qemu Qemu 0.11.0-rc2 (including) 0.11.0-rc2 (including)
Qemu Qemu 0.11.1 (including) 0.11.1 (including)
Qemu Qemu 0.12.0 (including) 0.12.0 (including)
Qemu Qemu 0.12.0-rc1 (including) 0.12.0-rc1 (including)
Qemu Qemu 0.12.0-rc2 (including) 0.12.0-rc2 (including)
Qemu Qemu 0.12.1 (including) 0.12.1 (including)
Qemu Qemu 0.12.2 (including) 0.12.2 (including)
Qemu Qemu 0.12.3 (including) 0.12.3 (including)
Qemu Qemu 0.12.4 (including) 0.12.4 (including)
Qemu Qemu 0.12.5 (including) 0.12.5 (including)
Qemu Qemu 0.13.0 (including) 0.13.0 (including)
Qemu Qemu 0.13.0-rc0 (including) 0.13.0-rc0 (including)
Qemu Qemu 0.13.0-rc1 (including) 0.13.0-rc1 (including)
Qemu Qemu 0.14.0-rc0 (including) 0.14.0-rc0 (including)
Qemu Qemu 0.14.0-rc1 (including) 0.14.0-rc1 (including)
Qemu Qemu 0.14.0-rc2 (including) 0.14.0-rc2 (including)
Qemu Qemu 0.14.1 (including) 0.14.1 (including)
Qemu Qemu 0.15.0-rc1 (including) 0.15.0-rc1 (including)
Qemu Qemu 0.15.0-rc2 (including) 0.15.0-rc2 (including)

References