4.9
CVSSv2

CVE-2008-2004

Published: 12/05/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted.

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 0.9.1

Vendor Advisories

USN-776-1 fixed vulnerabilities in KVM Due to an incorrect fix, a regression was introduced in Ubuntu 804 LTS that caused KVM to fail to boot virtual machines started via libvirt This update fixes the problem We apologize for the inconvenience ...
Avi Kivity discovered that KVM did not correctly handle certain disk formats A local attacker could attach a malicious partition that would allow the guest VM to read files on the VM host (CVE-2008-1945, CVE-2008-2004) ...
Debian Bug report logs - #481204 kvm: CVE-2008-2004 allows unauthorized disclosure of information Package: kvm; Maintainer for kvm is (unknown); Reported by: Nico Golde <nion@debianorg> Date: Wed, 14 May 2008 14:12:01 UTC Severity: grave Tags: patch, security Fixed in version kvm/66+dfsg-11 Done: Steffen Joeris <whi ...
Debian Bug report logs - #526013 qemu: CVE-2008-1945 media handling vulnerability Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 28 Apr 2009 17 ...
Debian Bug report logs - #705544 CVE-2013-1922 -- qemu-nbd block format auto-detection vulnerability Package: qemu-utils; Maintainer for qemu-utils is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu-utils is src:qemu (PTS, buildd, popcon) Reported by: Michael Tokarev <mjt@tlsmskru> Date: ...