Novell Home

CVE-2008-2004

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2008-2004 at MITRE

Description

The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted.

NVD CVSS v2 Base Score: 4.9 (AV:L/AC:L/Au:N/C:C/I:N/A:N)

Novell/SUSE information

Novell Bugzilla entry: 380828

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE LINUX 10.1
  • qemu >= 0.8.0-14.4
openSUSE 10.2
  • qemu >= 0.8.2-34.4
openSUSE 10.3
  • qemu >= 0.9.0.cvs-35.2

© 2012 Novell