First published: Fri Aug 08 2008(Updated: )
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU qemu | =0.9.0 | |
openSUSE openSUSE | =11.1 | |
openSUSE openSUSE | =11.0 | |
openSUSE openSUSE | =10.3 | |
SUSE Linux Enterprise Server | =11 | |
SUSE Linux Enterprise Server | =10 | |
Debian Debian Linux | =5.0 | |
Debian Debian Linux | =4.0 | |
Canonical Ubuntu Linux | =8.10 | |
Canonical Ubuntu Linux | =8.04 | |
Redhat Enterprise Linux Server | =5.0 | |
Redhat Enterprise Linux Workstation | =5.0 | |
Redhat Enterprise Linux Desktop | =5.0 | |
Redhat Enterprise Linux Eus | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.