2.1
CVSSv2

CVE-2008-1945

Published: 08/08/2008 Updated: 16/12/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 0.9.0

opensuse opensuse 10.3

opensuse opensuse 11.0

opensuse opensuse 11.1

suse linux enterprise server 10

suse linux enterprise server 11

debian debian linux 4.0

debian debian linux 5.0

canonical ubuntu linux 8.04

canonical ubuntu linux 8.10

redhat enterprise linux desktop 5.0

redhat enterprise linux eus 5.2

redhat enterprise linux server 5.0

redhat enterprise linux workstation 5.0

Vendor Advisories

Synopsis Important: xen security and bug fix update Type/Severity Security Advisory: Important Topic Updated xen packages that resolve a couple of security issues and fix a bugare now available for Red Hat Enterprise Linux 5This update has been rated as having important security impact by the RedHat Securi ...
Debian Bug report logs - #526040 qemu: CVE-2008-4539 buffer overlflow vulnerability Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 28 Apr 2009 ...
Debian Bug report logs - #526013 qemu: CVE-2008-1945 media handling vulnerability Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 28 Apr 2009 17 ...
USN-776-1 fixed vulnerabilities in KVM Due to an incorrect fix, a regression was introduced in Ubuntu 804 LTS that caused KVM to fail to boot virtual machines started via libvirt This update fixes the problem We apologize for the inconvenience ...
Avi Kivity discovered that KVM did not correctly handle certain disk formats A local attacker could attach a malicious partition that would allow the guest VM to read files on the VM host (CVE-2008-1945, CVE-2008-2004) ...