Back

HIGH

QEMU: dev-mtp: path traversal in usb_mtp_write_data of the Media Transfer Protocol (MTP)

Published Dec 12, 2018

Description

A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code execution on the host.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 12, 2018
Updated Aug 5, 2024
Reserved Sep 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 3, 2018
ENISA EUVD
Assigner redhat
Published Dec 12, 2018
Updated Aug 5, 2024
Exploited since n/a
EUVD-2018-8658