A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code execution on the host.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 12, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade qemu-block-iscsiUpgrade qemu-ui-cursesUpgrade qemu-block-dmgUpgrade qemu-kvmUpgrade qemu-ui-gtkUpgrade qemu-ui-sdlUpgrade qemu-audio-alsaUpgrade qemu-system-aarch64-coreUpgrade qemu-block-curlUpgrade qemu-audio-sdlUpgrade qemu-imgUpgrade qemu-block-glusterUpgrade qemu-block-rbdUpgrade qemu-block-nfsUpgrade qemu-audio-paUpgrade qemu-commonUpgrade qemu-block-sshUpgrade qemu-audio-ossUpgrade qemu-system-aarch64 | Aug 28, 2019 | Dec 12, 2018 |
| Oracle_linux | — | Upgrade qemu-system-x86Upgrade qemu-system-aarch64Upgrade qemu-imgUpgrade qemu-kvm-coreUpgrade qemu-system-aarch64-coreUpgrade ivshmem-toolsUpgrade qemuUpgrade qemu-commonUpgrade qemu-kvmUpgrade qemu-system-x86-coreUpgrade qemu-block-glusterUpgrade qemu-block-iscsiUpgrade qemu-block-rbd | Dec 23, 2018 | Dec 3, 2018 |
| Ubuntu | — | Upgrade qemu-system-guiUpgrade qemu-system-s390xUpgrade qemu-system-x86Upgrade qemu-system-ppcUpgrade qemu-systemUpgrade qemu-system-miscUpgrade qemu-system-armUpgrade qemu-system-dataUpgrade qemu-system-sparcUpgrade qemu-system-aarch64Upgrade qemu-system-mips | Apr 3, 2019 | Dec 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub