A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code execution on the host.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 12, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade qemu-block-nfsUpgrade qemu-audio-paUpgrade qemu-block-rbdUpgrade qemu-block-sshUpgrade qemu-audio-ossUpgrade qemu-commonUpgrade qemu-system-aarch64Upgrade qemu-block-glusterUpgrade qemu-ui-gtkUpgrade qemu-kvmUpgrade qemu-block-curlUpgrade qemu-ui-cursesUpgrade qemu-block-dmgUpgrade qemu-audio-sdlUpgrade qemu-ui-sdlUpgrade qemu-system-aarch64-coreUpgrade qemu-audio-alsaUpgrade qemu-imgUpgrade qemu-block-iscsi | Aug 28, 2019 | Dec 12, 2018 |
| Oracle_linux | — | Upgrade qemu-system-aarch64Upgrade qemu-system-aarch64-coreUpgrade qemu-system-x86Upgrade qemu-kvm-coreUpgrade qemu-imgUpgrade qemu-commonUpgrade qemuUpgrade qemu-block-glusterUpgrade qemu-block-iscsiUpgrade qemu-system-x86-coreUpgrade ivshmem-toolsUpgrade qemu-kvmUpgrade qemu-block-rbd | Dec 23, 2018 | Dec 3, 2018 |
| Ubuntu | — | Upgrade qemu-system-ppcUpgrade qemu-system-miscUpgrade qemu-system-guiUpgrade qemu-system-dataUpgrade qemu-system-x86Upgrade qemu-system-s390xUpgrade qemu-system-armUpgrade qemu-systemUpgrade qemu-system-sparcUpgrade qemu-system-mipsUpgrade qemu-system-aarch64 | Apr 3, 2019 | Dec 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub