4.7
CVSSv2

CVE-2010-3851

Published: 04/11/2010 Updated: 27/08/2011
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
VMScore: 418
Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

libguestfs prior to 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and previous versions, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libguestfs libguestfs 1.5.20

libguestfs libguestfs 1.5.21

libguestfs libguestfs 1.5.15

libguestfs libguestfs 1.5.14

libguestfs libguestfs 1.5.9

libguestfs libguestfs 1.5.6

libguestfs libguestfs

libguestfs libguestfs 1.5.0

libguestfs libguestfs 1.5.1

libguestfs libguestfs 1.5.19

libguestfs libguestfs 1.5.18

libguestfs libguestfs 1.5.10

libguestfs libguestfs 1.5.5

libguestfs libguestfs 1.5.17

libguestfs libguestfs 1.5.16

libguestfs libguestfs 1.5.8

libguestfs libguestfs 1.5.11

libguestfs libguestfs 1.5.2

libguestfs libguestfs 1.5.3

libguestfs libguestfs 1.5.13

libguestfs libguestfs 1.5.12

libguestfs libguestfs 1.5.4

libguestfs libguestfs 1.5.7