CVE-2012-2652

The bdrv_open function in Qemu 1.0 does not properly handle the failure of the mkstemp function, when in snapshot node, which allows local users to overwrite or read arbitrary files via a symlink attack on an unspecified temporary file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:qemu:qemu:1.0:*:*:*:*:*:*:*

History

13 Feb 2023, 00:25

Type Values Removed Values Added
References
  • {'url': 'http://git.qemu.org/?p=qemu-stable-0.15.git;a=log', 'name': 'http://git.qemu.org/?p=qemu-stable-0.15.git;a=log', 'tags': [], 'refsource': 'CONFIRM'}
  • {'url': 'http://git.kernel.org/?p=virt/kvm/qemu-kvm.git;a=commit;h=eba25057b9a5e19d10ace2bc7716667a31297169', 'name': 'http://git.kernel.org/?p=virt/kvm/qemu-kvm.git;a=commit;h=eba25057b9a5e19d10ace2bc7716667a31297169', 'tags': [], 'refsource': 'CONFIRM'}
  • (MISC) http://git.kernel.org/?p=virt/kvm/qemu-kvm.git%3Ba=commit%3Bh=eba25057b9a5e19d10ace2bc7716667a31297169 -
  • (MISC) http://git.qemu.org/?p=qemu-stable-0.15.git%3Ba=log -

Information

Published : 2012-08-07 20:55

Updated : 2023-12-10 11:16


NVD link : CVE-2012-2652

Mitre link : CVE-2012-2652

CVE.ORG link : CVE-2012-2652


JSON object : View

Products Affected

qemu

  • qemu