A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code execution on the host.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qemu | Jul 30, 2024 | Dec 12, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade qemu-kvmUpgrade qemu-audio-sdlUpgrade qemu-system-aarch64-coreUpgrade qemu-audio-alsaUpgrade qemu-imgUpgrade qemu-ui-gtkUpgrade qemu-block-curlUpgrade qemu-ui-cursesUpgrade qemu-block-iscsiUpgrade qemu-ui-sdlUpgrade qemu-block-dmgUpgrade qemu-system-aarch64Upgrade qemu-commonUpgrade qemu-block-rbdUpgrade qemu-audio-paUpgrade qemu-block-nfsUpgrade qemu-block-glusterUpgrade qemu-block-sshUpgrade qemu-audio-oss | Aug 28, 2019 | Dec 12, 2018 |
| Oracle_linux | — | Upgrade qemuUpgrade qemu-kvmUpgrade qemu-commonUpgrade ivshmem-toolsUpgrade qemu-block-iscsiUpgrade qemu-system-x86-coreUpgrade qemu-block-glusterUpgrade qemu-block-rbdUpgrade qemu-system-aarch64-coreUpgrade qemu-system-x86Upgrade qemu-imgUpgrade qemu-kvm-coreUpgrade qemu-system-aarch64 | Dec 23, 2018 | Dec 3, 2018 |
| Ubuntu | — | Upgrade qemu-system-ppcUpgrade qemu-system-miscUpgrade qemu-systemUpgrade qemu-system-dataUpgrade qemu-system-guiUpgrade qemu-system-s390xUpgrade qemu-system-armUpgrade qemu-system-x86Upgrade qemu-system-aarch64Upgrade qemu-system-mipsUpgrade qemu-system-sparc | Apr 3, 2019 | Dec 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub