CVE-2008-1945
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different…
Does this matter?
Lower severity and a low EPSS score (0.47%). Track it; it rarely justifies an emergency change on its own.
Description
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Affected
- qemu/qemu · opensuse/opensuse · suse/linux enterprise server · debian/debian linux · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/32063Third Party Advisory
- http://secunia.com/advisories/32088Third Party Advisory
- http://secunia.com/advisories/34642Third Party Advisory
- http://secunia.com/advisories/35031Third Party Advisory
- http://secunia.com/advisories/35062Third Party Advisory
- http://www.debian.org/security/2009/dsa-1799Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:162Third Party Advisory
- http://www.securityfocus.com/bid/30604Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020959Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-776-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44269Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9905Third Party Advisory
- https://rhn.redhat.com/errata/RHSA-2008-0892.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/32063Third Party Advisory
- http://secunia.com/advisories/32088Third Party Advisory
- http://secunia.com/advisories/34642Third Party Advisory
- http://secunia.com/advisories/35031Third Party Advisory
- http://secunia.com/advisories/35062Third Party Advisory
- http://www.debian.org/security/2009/dsa-1799Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:162Third Party Advisory
- http://www.securityfocus.com/bid/30604Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020959Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-776-1Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44269Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9905Third Party Advisory
- https://rhn.redhat.com/errata/RHSA-2008-0892.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.