A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code execution on the host.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 12, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade qemu-system-aarch64-coreUpgrade qemu-audio-alsaUpgrade qemu-ui-gtkUpgrade qemu-ui-sdlUpgrade qemu-kvmUpgrade qemu-block-curlUpgrade qemu-imgUpgrade qemu-block-dmgUpgrade qemu-ui-cursesUpgrade qemu-block-iscsiUpgrade qemu-audio-sdlUpgrade qemu-commonUpgrade qemu-system-aarch64Upgrade qemu-audio-ossUpgrade qemu-block-glusterUpgrade qemu-block-rbdUpgrade qemu-audio-paUpgrade qemu-block-nfsUpgrade qemu-block-ssh | Aug 28, 2019 | Dec 12, 2018 |
| Oracle_linux | — | Upgrade qemu-kvm-coreUpgrade qemu-imgUpgrade qemu-system-aarch64-coreUpgrade qemu-system-aarch64Upgrade qemu-system-x86Upgrade qemu-block-rbdUpgrade ivshmem-toolsUpgrade qemu-block-glusterUpgrade qemu-commonUpgrade qemu-block-iscsiUpgrade qemuUpgrade qemu-kvmUpgrade qemu-system-x86-core | Dec 23, 2018 | Dec 3, 2018 |
| Ubuntu | — | Upgrade qemu-system-mipsUpgrade qemu-system-sparcUpgrade qemu-system-aarch64Upgrade qemu-system-x86Upgrade qemu-system-s390xUpgrade qemu-system-miscUpgrade qemu-systemUpgrade qemu-system-ppcUpgrade qemu-system-guiUpgrade qemu-system-armUpgrade qemu-system-data | Apr 3, 2019 | Dec 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub