Permissions, Privileges, and Access Controls in QEMU - CVE-2013-2007

 

Permissions, Privileges, and Access Controls in QEMU - CVE-2013-2007

Published: May 21, 2013 / Updated: July 28, 2020


Vulnerability identifier: #VU32665
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2007
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local non-authenticated attacker to execute arbitrary code.

The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.


Affected software

QEMU
qemu (Alpine package)

How to mitigate CVE-2013-2007

Install update from vendor's website.

qemu (Alpine package) - update to 0.15.1-r1

External References

Related Security Bulletins