libguestfs File Information Disclosure Vulnerability
BID:53932
Info
libguestfs File Information Disclosure Vulnerability
| Bugtraq ID: | 53932 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2690 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 12 2012 12:00AM |
| Updated: | Jul 03 2012 08:30AM |
| Credit: | Richard W.M. Jones in a Red Hat bug report. |
| Vulnerable: |
Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 |
| Not Vulnerable: | |
Discussion
libguestfs File Information Disclosure Vulnerability
libguestfs is prone to an information disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
libguestfs 1.16.4 is vulnerable; other versions may also be affected.
libguestfs is prone to an information disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may lead to further attacks.
libguestfs 1.16.4 is vulnerable; other versions may also be affected.
Exploit / POC
libguestfs File Information Disclosure Vulnerability
Attackers can use readily available tools and standard commands to exploit this issue.
Attackers can use readily available tools and standard commands to exploit this issue.
Solution / Fix
libguestfs File Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
libguestfs File Information Disclosure Vulnerability
References:
References: