MEDIUM
libguestfs: missing disk format specifier when adding a disk
Published Nov 4, 2010
4.7
MEDIUMCVSS 2.0
EPSS 0.37%
Description
libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.
Affected products
No data.
AND
OR
- ≤ 1.5.22
- 1.5.0
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.5.5
- 1.5.6
- 1.5.7
- 1.5.8
- 1.5.9
- 1.5.10
- 1.5.11
- 1.5.12
- 1.5.13
- 1.5.14
- 1.5.15
- 1.5.16
- 1.5.17
- 1.5.18
- 1.5.19
- 1.5.20
- 1.5.21
Running on/with
OR
- n/a
- ≤ 1.5.3
No data.
Red Hat Enterprise Linux 6
libguestfs-1:1.7.17-17.el6
Fixed · RHSA-2011:0586
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | libguestfs-1:1.7.17-17.el6 | Fixed | RHSA-2011:0586 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (17)
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050237.html vendor-advisoryx_refsource_FEDORAPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050742.html vendor-advisoryx_refsource_FEDORA
- http://rwmj.wordpress.com/2010/10/23/new-libguestfs-stable-versions/ x_refsource_CONFIRM
- http://secunia.com/advisories/41797 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42235 third-party-advisoryx_refsource_SECUNIA
- http://www.redhat.com/support/errata/RHSA-2011-0586.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/44166 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2010/2874 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/2963 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-3851 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=643958 x_refsource_MISCIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-3830 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-3851
- https://www.cve.org/CVERecord?id=CVE-2010-3851
- https://www.redhat.com/archives/libguestfs/2010-October/msg00036.html mailing-listx_refsource_MLIST
- https://www.redhat.com/archives/libguestfs/2010-October/msg00037.html mailing-listx_refsource_MLIST
- https://www.redhat.com/archives/libguestfs/2010-October/msg00041.html mailing-listx_refsource_MLISTPatch
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 4, 2010
Updated Aug 7, 2024
Reserved Oct 8, 2010
Link CVE-2010-3851
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-3830 Assigner redhat
Published Nov 4, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-3830