vulnerability

Debian: CVE-2016-9602: qemu, qemu-kvm -- security update

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Apr 20, 2017
Added
May 30, 2017
Modified
Nov 27, 2024

Description

Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

Solution(s)

debian-upgrade-qemudebian-upgrade-qemu-kvm
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.