CVE Vulnerabilities

CVE-2013-2007

Published: May 21, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.2 MODERATE
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
LOW

The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.

Affected Software

Name Vendor Start Version End Version
Qemu Qemu 1.4.1 (including) 1.4.1 (including)
Red Hat Enterprise Linux 6 RedHat qemu-kvm-2:0.12.1.2-2.355.el6_4.5 *
Qemu Ubuntu raring *
Qemu Ubuntu upstream *
Qemu-kvm Ubuntu precise *
Qemu-kvm Ubuntu upstream *
Xen Ubuntu upstream *
Xen-3.3 Ubuntu upstream *

References