Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 483216 (CVE-2013-2007)

Summary: <app-emulation/qemu-1.4.1 : Weak File Permissions (CVE-2013-2007)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [noglsa]
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2013-09-01 00:02:43 UTC
CVE-2013-2007 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2007):
  The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started
  in daemon mode, uses weak permissions for certain files, which allows local
  users to read and write to these files.
Comment 1 Chris Reffett (RETIRED) gentoo-dev Security 2013-09-01 00:05:26 UTC
Also can affect Xen, but [1] says that this is really not a default configuration and requires a lot of work on the part of the systems administrator. Removing maintainers since they don't need to be CC'd. GLSA vote: no.

[1] http://www.openwall.com/lists/oss-security/2013/05/06/5
Comment 2 Sergey Popov gentoo-dev 2013-09-02 10:30:11 UTC
GLSA vote: no

Closing as noglsa.