Upstream information
Description
The change_process_uid function in os-posix.c in Qemu 0.14.0 and earlier does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.NVD CVSS v2 Base Score: 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Novell Bugzilla entry: 705304 SUSE Security Advisories:- openSUSE-SU-2012:0207-1, published Thu, 9 Feb 2012 19:09:50 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Studio Extension for System z 1.2 |
| studioonsite1.2.s390x SAT Patch Nr: 5656 |
| SLE 11 SP1 DEBUGINFO |
| sles11-sp1.x86 sled11-sp1.x86 sles11-sp1.x86-64 sled11-sp1.x86-64 SAT Patch Nr: 5655 |
| SUSE Linux Enterprise Desktop 11 SP1 SUSE Linux Enterprise Server 11 SP1 |
| sles11-sp1.x86 sled11-sp1.x86 sles11-sp1.x86-64 sled11-sp1.x86-64 SAT Patch Nr: 5655 |
| openSUSE 11.4 DEBUGINFO |
| |
| openSUSE 11.4 |
|
