4.7
CVSSv3

CVE-2013-1922

CVSSv4: NA | CVSSv3: 4.7 | CVSSv2: 3.3 | VMScore: 430 | EPSS: 0.00079 | KEV: Not Included
Published: 13/05/2013 Updated: 21/11/2024

Vulnerability Summary

qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xen xen 4.2.0

xen xen 4.2.1

xen xen 4.2.2

Vendor Advisories

Debian Bug report logs - #705544 CVE-2013-1922 -- qemu-nbd block format auto-detection vulnerability Package: qemu-utils; Maintainer for qemu-utils is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu-utils is src:qemu (PTS, buildd, popcon) Reported by: Michael Tokarev <mjt@tlsmskru> Date: ...
qemu-nbd in QEMU, as used in Xen 42x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted, a different vulnerability than CVE-2008-2004 ...