A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code execution on the host.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 12, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade qemu-ui-gtkUpgrade qemu-block-curlUpgrade qemu-imgUpgrade qemu-kvmUpgrade qemu-audio-sdlUpgrade qemu-block-dmgUpgrade qemu-ui-cursesUpgrade qemu-block-iscsiUpgrade qemu-system-aarch64-coreUpgrade qemu-audio-alsaUpgrade qemu-ui-sdlUpgrade qemu-block-sshUpgrade qemu-block-glusterUpgrade qemu-system-aarch64Upgrade qemu-commonUpgrade qemu-audio-ossUpgrade qemu-block-rbdUpgrade qemu-audio-paUpgrade qemu-block-nfs | Aug 28, 2019 | Dec 12, 2018 |
| Oracle_linux | — | Upgrade qemu-system-x86Upgrade qemu-system-aarch64Upgrade qemu-system-aarch64-coreUpgrade qemu-imgUpgrade qemu-kvm-coreUpgrade qemu-kvmUpgrade qemu-block-rbdUpgrade ivshmem-toolsUpgrade qemuUpgrade qemu-commonUpgrade qemu-block-iscsiUpgrade qemu-block-glusterUpgrade qemu-system-x86-core | Dec 23, 2018 | Dec 3, 2018 |
| Ubuntu | — | Upgrade qemu-systemUpgrade qemu-system-miscUpgrade qemu-system-dataUpgrade qemu-system-guiUpgrade qemu-system-ppcUpgrade qemu-system-armUpgrade qemu-system-x86Upgrade qemu-system-s390xUpgrade qemu-system-aarch64Upgrade qemu-system-sparcUpgrade qemu-system-mips | Apr 3, 2019 | Dec 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub