RETIRED: QEMU Guest Agent CVE-2013-2007 Insecure File Permissions Vulnerability
BID:59707
Info
RETIRED: QEMU Guest Agent CVE-2013-2007 Insecure File Permissions Vulnerability
| Bugtraq ID: | 59707 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 24 2013 12:00AM |
| Updated: | May 22 2013 02:43PM |
| Credit: | The vendor reported this issue |
| Vulnerable: |
QEMU QEMU 0.10.6 QEMU QEMU 0.9.1 QEMU QEMU 0.9 QEMU QEMU 0.8.2 QEMU QEMU 0.6.1 QEMU QEMU 1.1 QEMU QEMU 0.10 |
| Not Vulnerable: | |
Discussion
RETIRED: QEMU Guest Agent CVE-2013-2007 Insecure File Permissions Vulnerability
QEMU is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information and modify or delete logs. Information obtained may aid in further attacks.
QEMU 1.4.1 and prior are vulnerable.
Note: This BID is being retired as a duplicate of the issue discussed in BID 59675 (QEMU Guest Agent CVE-2013-2007 Insecure File Permissions Vulnerability).
QEMU is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information and modify or delete logs. Information obtained may aid in further attacks.
QEMU 1.4.1 and prior are vulnerable.
Note: This BID is being retired as a duplicate of the issue discussed in BID 59675 (QEMU Guest Agent CVE-2013-2007 Insecure File Permissions Vulnerability).
Exploit / POC
RETIRED: QEMU Guest Agent CVE-2013-2007 Insecure File Permissions Vulnerability
An attacker requires local interactive access to the affected application to exploit this issue.
An attacker requires local interactive access to the affected application to exploit this issue.
Solution / Fix
RETIRED: QEMU Guest Agent CVE-2013-2007 Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
RETIRED: QEMU Guest Agent CVE-2013-2007 Insecure File Permissions Vulnerability
References:
References:
- QEMU Homepage (QEMU)