CVE Vulnerabilities

CVE-2013-2007

Published: May 21, 2013 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.2 MODERATE
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
LOW

The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu 1.4.1 (including) 1.4.1 (including)
Red Hat Enterprise Linux 6 RedHat qemu-kvm-2:0.12.1.2-2.355.el6_4.5 *
Qemu Ubuntu raring *
Qemu Ubuntu upstream *
Qemu-kvm Ubuntu precise *
Qemu-kvm Ubuntu upstream *
Xen Ubuntu upstream *
Xen-3.3 Ubuntu upstream *

References