LOW · 2.1

CVE-2008-1945

QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify...

Vulnerability Description

QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different format, a related issue to CVE-2008-2004.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
QemuQemu0.9.0
OpensuseOpensuse10.3
SuseLinux Enterprise Server10
DebianDebian Linux4.0
CanonicalUbuntu Linux8.04
RedhatEnterprise Linux Desktop5.0
RedhatEnterprise Linux Eus5.2
RedhatEnterprise Linux Server5.0
RedhatEnterprise Linux Workstation5.0

References

FAQ

What is CVE-2008-1945?

CVE-2008-1945 is a vulnerability with a CVSS score of 2.1 (LOW). QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify...

How severe is CVE-2008-1945?

CVE-2008-1945 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-1945?

Check the references section above for vendor advisories and patch information. Affected products include: Qemu Qemu, Opensuse Opensuse, Suse Linux Enterprise Server, Debian Debian Linux, Canonical Ubuntu Linux.