Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 430456 (CVE-2012-2652)

Summary: <app-emulation/qemu-kvm-1.1.1-r1 : symlink vulnerability (CVE-2012-2652)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: qemu+disabled
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: C1 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on: 428476    
Bug Blocks:    

Description GLSAMaker/CVETool Bot gentoo-dev 2012-08-08 14:10:14 UTC
CVE-2012-2652 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-2652):
  The bdrv_open function in Qemu 1.0 does not properly handle the failure of
  the mkstemp function, when in snapshot node, which allows local users to
  overwrite or read arbitrary files via a symlink attack on an unspecified
  temporary file.
Comment 1 Agostino Sarubbo gentoo-dev 2012-08-08 15:14:40 UTC
@who_has_Opened_this_bug:

Since is marked as [ebuild] would be great if you mention the fixed version next time
Comment 2 Doug Goldstein (RETIRED) gentoo-dev 2012-08-08 17:51:11 UTC
The referenced commit that fixes this appears in the 1.1 release. 1.1.1-r1 is stable on amd64. We're waiting on x86 for bug #428476.
Comment 3 Sean Amoss (RETIRED) gentoo-dev Security 2012-09-23 14:36:17 UTC
Thanks, everyone.

Already on existing GLSA draft.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2012-10-18 20:59:36 UTC
This issue was resolved and addressed in
 GLSA 201210-04 at http://security.gentoo.org/glsa/glsa-201210-04.xml
by GLSA coordinator Stefan Behte (craig).