qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | May 13, 2013 |
| Gentoo Linux | — | Upgrade app-emulation/xen.Upgrade app-emulation/xen-tools.Upgrade app-emulation/xen-pvgrub. | Oct 30, 2017 | May 13, 2013 |
| Suse | — | Upgrade xen-kmp-paeUpgrade xen-libsUpgrade xen-kmp-defaultUpgrade sle-sdk-releaseUpgrade xenUpgrade xen-tools-domUUpgrade xen-kmp-desktopUpgrade xen-libs-32bitUpgrade xen-doc-htmlUpgrade xen-doc-pdfUpgrade xen-toolsUpgrade xen-devel | Dec 12, 2013 | May 13, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub