libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.
References
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2010-11-04 18:00
Updated : 2011-08-27 03:44
NVD link : CVE-2010-3851
Mitre link : CVE-2010-3851
CVE.ORG link : CVE-2010-3851
JSON object : View
Products Affected
richard_jones
- virt-inspector
matthew_booth
- virt-v2v
libguestfs
- libguestfs
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor