2.1
CVSSv2

CVE-2011-2527

Published: 21/06/2012 Updated: 02/11/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The change_process_uid function in os-posix.c in Qemu 0.14.0 and previous versions does not properly drop group privileges when the -runas option is used, which allows local guest users to access restricted files on the host.

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 0.12.4

qemu qemu 0.12.0

qemu qemu 0.11.0

qemu qemu 0.10.2

qemu qemu 0.9.1

qemu qemu 0.7.1

qemu qemu 0.7.0

qemu qemu 0.3.0

qemu qemu 0.2.0

qemu qemu 0.15.0

qemu qemu 0.1.5

qemu qemu 0.11.0-rc1

qemu qemu 0.13.0

qemu qemu 0.12.1

qemu qemu 0.10.5

qemu qemu 0.9.1-5

qemu qemu 0.9.0

qemu qemu 0.6.1

qemu qemu 0.6.0

qemu qemu

qemu qemu 0.12.3

qemu qemu 0.12.2

qemu qemu 0.10.4

qemu qemu 0.10.6

qemu qemu 0.8.0

qemu qemu 0.8.1

qemu qemu 0.4.1

qemu qemu 0.4.0

qemu qemu 0.1.1

qemu qemu 0.14.0

qemu qemu 0.12.5

qemu qemu 0.11.1

qemu qemu 0.10.1

qemu qemu 0.10.0

qemu qemu 0.10.3

qemu qemu 0.1.6

qemu qemu 0.1.2

qemu qemu 0.1.3

qemu qemu 0.1.4

qemu qemu 0.8.2

qemu qemu 0.7.2

qemu qemu 0.4.3

qemu qemu 0.4.2

qemu qemu 0.14.1

qemu qemu 0.1.0

qemu qemu 0.11.0-rc0

qemu qemu 0.11.0-rc2

Vendor Advisories

Synopsis Moderate: qemu-kvm security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated qemu-kvm packages that fix one security issue, multiple bugs, andadd various enhancements are now available for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rate ...
QEMU could be made to run with adminstrator group privileges under certain circumstances ...
Two vulnerabilities have been discovered in KVM, a solution for full virtualization on x86 hardware: CVE-2011-2212 Nelson Elhage discovered a buffer overflow in the virtio subsystem, which could lead to denial of service or privilege escalation CVE-2011-2527 Andrew Griffiths discovered that group privileges were insufficiently dropped ...