The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted.
References
Configurations
History
No history.
Information
Published : 2008-05-12 22:20
Updated : 2024-02-28 11:21
NVD link : CVE-2008-2004
Mitre link : CVE-2008-2004
CVE.ORG link : CVE-2008-2004
JSON object : View
Products Affected
qemu
- qemu
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor